Remote Authentication Bypass Vulnerability in Siemens WinCC Products
CVE-2012-3034

Currently unrated

Key Information:

Vendor
Siemens
Vendor
CVE Published:
18 September 2012

Summary

The WebNavigator component in Siemens WinCC versions 7.0 SP3 and earlier, utilized in SIMATIC PCS7 and similar products, has a vulnerability that enables remote attackers to exploit crafted parameters targeting unspecified ActiveX control methods. This exploitation could potentially lead to unauthorized access, allowing attackers to discern usernames and passwords, thereby compromising the security of the affected systems.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.