NetBIOS User Enumeration Vulnerability in Siemens WinCC
CVE-2013-3959

Currently unrated

Key Information:

Vendor
Siemens
Vendor
CVE Published:
14 June 2013

Summary

The Web Navigator in Siemens WinCC versions prior to 7.2 Update 1 displays inconsistent behavior with NetBIOS user names, contingent upon the existence of user accounts. This discrepancy enables remote authenticated users to exploit crafted URL parameters to enumerate user account names, posing a significant security risk for organizations relying on these systems. As a result, unverified users might gain insights into account structures, potentially leading to further exploitation or breaches.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.