Directory Traversal Vulnerability in Siemens WinCC Products
CVE-2011-4876

Currently unrated

Key Information:

Vendor
Siemens
Vendor
CVE Published:
3 February 2012

Summary

A directory traversal vulnerability exists in the HmiLoad component of Siemens WinCC flexible products, including the 2004-2008 versions and WinCC V11 (TIA Portal). When the Transfer Mode is enabled, this vulnerability allows remote attackers to manipulate file paths via the use of '../' sequences in input strings. This could enable unauthorized file execution, reading, modification, or deletion, posing significant security risks to affected systems.

References

EPSS Score

14% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.