SQL Injection Vulnerability in Siemens WinCC and SIMATIC PCS7 Products
CVE-2013-3957

Currently unrated

Key Information:

Vendor
Siemens
Vendor
CVE Published:
14 June 2013

Summary

The SQL injection vulnerability in the login screen of Siemens WinCC allows remote attackers to execute arbitrary SQL commands. This flaw is present in versions prior to 7.2 Update 1 and affects SIMATIC PCS7 8.0 SP1 and earlier. Attackers can exploit this vulnerability through unspecified vectors, potentially leading to unauthorized access and manipulation of sensitive data. It's crucial for users to apply necessary updates to mitigate exposure to this security risk.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.