CVE-2012-3003: Input Validation
Published Jun 8, 2012
·Updated
Open redirect vulnerability in an unspecified web application in Siemens WinCC 7.0 SP3 before Update 2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a GET request.
Affected Software
2 affected components
Siemens WinCC=7.0-sp3
Siemens WinCC=7.0-sp3
Event History
Jun 8, 2012
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-3003?
CVE-2012-3003 is considered a medium severity vulnerability as it allows for open redirection, potentially leading to phishing attacks.
2
How do I fix CVE-2012-3003?
To fix CVE-2012-3003, upgrade Siemens WinCC to version 7.0 SP3 Update 2 or later.
3
What type of vulnerability is CVE-2012-3003?
CVE-2012-3003 is an open redirect vulnerability affecting Siemens WinCC applications.
4
Who is affected by CVE-2012-3003?
CVE-2012-3003 affects users of Siemens WinCC 7.0 SP3 before Update 2.
5
What are the potential impacts of CVE-2012-3003?
The potential impacts of CVE-2012-3003 include unauthorized redirection of users to malicious websites, leading to phishing attacks.