Hardcoded Account Vulnerability in Siemens WinCC and SIMATIC PCS7
CVE-2013-3958
Currently unrated
Summary
A vulnerability exists in the login implementation of the Web Navigator in Siemens WinCC prior to version 7.2 Update 1, as well as in SIMATIC PCS7 8.0 SP1 and earlier. This design flaw includes a hardcoded account, allowing remote attackers to potentially gain unauthorized access via unspecified requests. This could lead to significant security risks, emphasizing the importance of timely updates and proper security practices.
References
Timeline
Vulnerability Reserved
Vulnerability published