CVE-2011-4879: Input Validation
miniweb.exe in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime does not properly handle URIs beginning with a 0xfa character, which allows remote attackers to read data from arbitrary memory locations or cause a denial of service (application crash) via a crafted POST request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4879?
CVE-2011-4879 has a critical severity rating due to potential remote code execution vulnerabilities.
How do I fix CVE-2011-4879?
To address CVE-2011-4879, update all affected Siemens WinCC flexible versions and SIMATIC HMI panels to the latest patches.
What products are affected by CVE-2011-4879?
CVE-2011-4879 affects Siemens WinCC flexible versions 2004 through 2008, WinCC V11 before SP2 Update 1, and various SIMATIC HMI panels.
Is CVE-2011-4879 actively exploited?
As of the latest information, CVE-2011-4879 is considered a vulnerability that could be exploited, emphasizing the need for timely updates.
What are the consequences of CVE-2011-4879?
Exploitation of CVE-2011-4879 may allow an attacker to execute arbitrary code on affected systems, leading to unauthorized access or control.