Directory Traversal Vulnerability in Siemens WinCC and SIMATIC Products
CVE-2013-0679

Currently unrated

Key Information:

Vendor
Siemens
Vendor
CVE Published:
21 March 2013

Summary

A directory traversal vulnerability exists in the Siemens WinCC web server prior to version 7.2. This flaw also affects SIMATIC PCS7 versions preceding 8.0 SP1, enabling remote authenticated users to navigate outside the intended directory structure. By exploiting this vulnerability, attackers can craft specific queries that allow them to access unauthorized files on the server, potentially compromising sensitive information. Proper configuration and security measures are essential to mitigate the risks associated with this vulnerability.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.