CVE-2012-2598: Buffer Overflow
Published Jun 8, 2012
·Updated
Buffer overflow in the DiagAgent web server in Siemens WinCC 7.0 SP3 through Update 2 allows remote attackers to cause a denial of service (agent outage) via crafted input.
Affected Software
3 affected components
Siemens WinCC=7.0-sp3
Siemens WinCC=7.0-sp3
Siemens WinCC=7.0-sp3
Event History
Jun 8, 2012
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-2598?
CVE-2012-2598 is classified as a high-severity vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2012-2598?
To fix CVE-2012-2598, update Siemens WinCC to a version greater than 7.0 SP3 Update 2.
3
What type of attack does CVE-2012-2598 allow?
CVE-2012-2598 allows remote attackers to exploit a buffer overflow to cause an outage of the DiagAgent web server.
4
Which versions of Siemens WinCC are affected by CVE-2012-2598?
Siemens WinCC 7.0 SP3 and its updates, specifically Update 1 and Update 2, are affected by CVE-2012-2598.
5
Can CVE-2012-2598 be exploited remotely?
Yes, CVE-2012-2598 can be exploited remotely through crafted input sent to the DiagAgent web server.