Authentication Bypass Vulnerability in Siemens HMI Web Server
CVE-2011-4508

Currently unrated

Key Information:

Vendor
Siemens
Vendor
CVE Published:
3 February 2012

Summary

The HMI web server in various Siemens WinCC products is susceptible to an authentication bypass due to the generation of predictable authentication tokens for cookies. This vulnerability allows remote attackers to craft specific cookies that facilitate bypassing the authentication mechanism, leading to unauthorized access to sensitive functionalities within impacted systems. Awareness and prompt remediation are essential to mitigate the risks associated with this vulnerability.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.