CRLF Injection Vulnerability in Siemens WinCC HMI Web Application
CVE-2013-0670

Currently unrated

Key Information:

Vendor
Siemens
Vendor
CVE Published:
21 March 2013

Summary

The CRLF injection vulnerability in the HMI web application of Siemens WinCC (TIA Portal) 11 enables remote attackers to inject arbitrary HTTP headers, potentially leading to HTTP response splitting attacks. By crafting a specific URL, an attacker could manipulate the HTTP response, which may result in the execution of unauthorized actions or the exposure of sensitive information.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.