First published: Fri Jun 08 2012(Updated: )
Buffer overflow in the DiagAgent web server in Siemens WinCC 7.0 SP3 through Update 2 allows remote attackers to cause a denial of service (agent outage) via crafted input.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens WinCC | =7.0-sp3 | |
Siemens WinCC | =7.0-sp3 | |
Siemens WinCC | =7.0-sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2598 is classified as a high-severity vulnerability due to its potential to cause a denial of service.
To fix CVE-2012-2598, update Siemens WinCC to a version greater than 7.0 SP3 Update 2.
CVE-2012-2598 allows remote attackers to exploit a buffer overflow to cause an outage of the DiagAgent web server.
Siemens WinCC 7.0 SP3 and its updates, specifically Update 1 and Update 2, are affected by CVE-2012-2598.
Yes, CVE-2012-2598 can be exploited remotely through crafted input sent to the DiagAgent web server.