Directory Traversal Vulnerability in Siemens WinCC and SIMATIC Products
CVE-2013-0679
Currently unrated
Summary
A directory traversal vulnerability exists in the Siemens WinCC web server prior to version 7.2. This flaw also affects SIMATIC PCS7 versions preceding 8.0 SP1, enabling remote authenticated users to navigate outside the intended directory structure. By exploiting this vulnerability, attackers can craft specific queries that allow them to access unauthorized files on the server, potentially compromising sensitive information. Proper configuration and security measures are essential to mitigate the risks associated with this vulnerability.
References
Timeline
Vulnerability Reserved
Vulnerability published