NetBIOS User Enumeration Vulnerability in Siemens WinCC
CVE-2013-3959
Currently unrated
Summary
The Web Navigator in Siemens WinCC versions prior to 7.2 Update 1 displays inconsistent behavior with NetBIOS user names, contingent upon the existence of user accounts. This discrepancy enables remote authenticated users to exploit crafted URL parameters to enumerate user account names, posing a significant security risk for organizations relying on these systems. As a result, unverified users might gain insights into account structures, potentially leading to further exploitation or breaches.
References
Timeline
Vulnerability Reserved
Vulnerability published