SQL Injection Vulnerability in Siemens WinCC and SIMATIC Products
CVE-2012-3032

Currently unrated

Key Information:

Vendor
Siemens
Vendor
CVE Published:
18 September 2012

Summary

An SQL injection vulnerability exists within the WebNavigator component of Siemens WinCC, where malicious actors can exploit this flaw by crafting specially designed SOAP messages. This allows them to execute arbitrary SQL commands, potentially compromising the integrity and confidentiality of the affected systems, including SIMATIC PCS7 and earlier versions of WinCC 7.0 SP3.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.