Hardcoded Account Vulnerability in Siemens WinCC and SIMATIC PCS7
CVE-2013-3958

Currently unrated

Key Information:

Vendor
Siemens
Vendor
CVE Published:
14 June 2013

Summary

A vulnerability exists in the login implementation of the Web Navigator in Siemens WinCC prior to version 7.2 Update 1, as well as in SIMATIC PCS7 8.0 SP1 and earlier. This design flaw includes a hardcoded account, allowing remote attackers to potentially gain unauthorized access via unspecified requests. This could lead to significant security risks, emphasizing the importance of timely updates and proper security practices.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.