Siemens SIMATIC WinCC And PCS 7 CVE-2013-3959 Username Enumeration Weakness
BID:60559
Info
Siemens SIMATIC WinCC And PCS 7 CVE-2013-3959 Username Enumeration Weakness
| Bugtraq ID: | 60559 |
| Class: | Design Error |
| CVE: |
CVE-2013-3959 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 14 2013 12:00AM |
| Updated: | Mar 19 2015 09:11AM |
| Credit: | Alexander Tlyapov from Positive Technologies |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Siemens SIMATIC WinCC And PCS 7 CVE-2013-3959 Username Enumeration Weakness
Siemens SIMATIC WinCC And PCS 7 are prone to a username-enumeration weakness because of a design error in the application when verifying user-supplied input.
Attackers may exploit this weakness to discern valid usernames. This may aid brute-force password cracking or other attacks.
Siemens SIMATIC WinCC And PCS 7 are prone to a username-enumeration weakness because of a design error in the application when verifying user-supplied input.
Attackers may exploit this weakness to discern valid usernames. This may aid brute-force password cracking or other attacks.
References
Siemens SIMATIC WinCC And PCS 7 CVE-2013-3959 Username Enumeration Weakness
References:
References:
- Siemens Homepage (Siemens)
- SIMATIC WinCC Homepage (Siemens)
- ICSA-13-169-02 - Siemens WinCC 7.2 Multiple Vulnerabilities (ICS-CERT)
- SSA-345843: Vulnerabilites in WinCC 7.2 (Siemens)