CVE-2012-2596: Code Injection
The XPath functionality in unspecified web applications in Siemens WinCC 7.0 SP3 before Update 2 does not properly handle special characters in parameters, which allows remote authenticated users to read or modify settings via a crafted URL, related to an "XML injection" attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2596?
CVE-2012-2596 is classified as a medium severity vulnerability due to its potential for unauthorized access and manipulation of settings.
How do I fix CVE-2012-2596?
To mitigate CVE-2012-2596, upgrade Siemens WinCC to version 7.0 SP3 Update 2 or later.
Can CVE-2012-2596 be exploited remotely?
Yes, CVE-2012-2596 can be exploited remotely by authenticated users through specially crafted URLs.
What type of attack is associated with CVE-2012-2596?
CVE-2012-2596 is associated with an XML injection attack due to improper handling of special characters.
Which versions of Siemens WinCC are affected by CVE-2012-2596?
CVE-2012-2596 affects Siemens WinCC version 7.0 SP3 prior to Update 2.