SQL Injection Vulnerability in Siemens WinCC and SIMATIC PCS7 Products
CVE-2013-3957
Currently unrated
Summary
The SQL injection vulnerability in the login screen of Siemens WinCC allows remote attackers to execute arbitrary SQL commands. This flaw is present in versions prior to 7.2 Update 1 and affects SIMATIC PCS7 8.0 SP1 and earlier. Attackers can exploit this vulnerability through unspecified vectors, potentially leading to unauthorized access and manipulation of sensitive data. It's crucial for users to apply necessary updates to mitigate exposure to this security risk.
References
Timeline
Vulnerability Reserved
Vulnerability published