CVE-2011-4876: Path Traversal
Directory traversal vulnerability in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime, when Transfer Mode is enabled, allows remote attackers to execute, read, create, modify, or delete arbitrary files via a .. (dot dot) in a string.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4876?
CVE-2011-4876 is considered a high severity vulnerability due to its potential for directory traversal attacks.
How do I fix CVE-2011-4876?
To address CVE-2011-4876, it is recommended to apply the appropriate patches provided by Siemens for the affected software versions.
What are the affected software versions for CVE-2011-4876?
CVE-2011-4876 affects Siemens WinCC flexible 2004, 2005, 2007, 2008, WinCC V11, and various SIMATIC HMI panels.
What type of vulnerability is CVE-2011-4876?
CVE-2011-4876 is a directory traversal vulnerability that allows attackers to access restricted files on the server.
Can CVE-2011-4876 impact industrial control systems?
Yes, CVE-2011-4876 can significantly impact industrial control systems that utilize affected Siemens software, leading to potential compromise.