CRLF Injection Vulnerability in Siemens WinCC HMI Web Server
CVE-2011-4512

Currently unrated

Key Information:

Vendor
Siemens
Vendor
CVE Published:
3 February 2012

Summary

A CRLF injection vulnerability exists in the HMI web server of Siemens WinCC, allowing remote attackers to exploit the system through unauthorized HTTP header insertion. The flaw affects various WinCC flexible versions and HMI panels, enabling potential HTTP response splitting attacks that could compromise system integrity and lead to further vulnerabilities.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.