CVE-2012-2595: XSS
Multiple cross-site scripting (XSS) vulnerabilities in unspecified web applications in Siemens WinCC 7.0 SP3 before Update 2 allow remote attackers to inject arbitrary web script or HTML via vectors involving special characters in parameters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2595?
CVE-2012-2595 has been classified with a medium severity due to its potential for remote exploitation through XSS vulnerabilities.
How do I fix CVE-2012-2595?
To fix CVE-2012-2595, upgrade to Siemens WinCC 7.0 SP3 Update 2 or later after ensuring all applications are updated.
What kind of attack can CVE-2012-2595 lead to?
CVE-2012-2595 allows attackers to inject arbitrary web scripts or HTML, potentially leading to session hijacking or phishing.
Is CVE-2012-2595 related to any specific versions of Siemens WinCC?
Yes, CVE-2012-2595 specifically affects Siemens WinCC 7.0 SP3 before Update 2.
Who is affected by the vulnerabilities described in CVE-2012-2595?
Any organizations using the affected versions of Siemens WinCC for web applications are vulnerable to CVE-2012-2595.