CRLF Injection Vulnerability in Siemens WinCC HMI Web Server
CVE-2011-4512
Currently unrated
Summary
A CRLF injection vulnerability exists in the HMI web server of Siemens WinCC, allowing remote attackers to exploit the system through unauthorized HTTP header insertion. The flaw affects various WinCC flexible versions and HMI panels, enabling potential HTTP response splitting attacks that could compromise system integrity and lead to further vulnerabilities.
References
Timeline
Vulnerability Reserved
Vulnerability published