Weak Default Password in Siemens WinCC HMI Web Server
CVE-2011-4509

Currently unrated

Key Information:

Vendor
Siemens
Vendor
CVE Published:
3 February 2012

Summary

The HMI web server within various Siemens WinCC products is exposed due to an improperly chosen default password for the administrator account. This vulnerability allows remote attackers to exploit the system by employing brute-force techniques based on numerous HTTP requests, potentially leading to unauthorized access and control over the affected devices.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.