First published: Tue Sep 18 2012(Updated: )
Cross-site request forgery (CSRF) vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to hijack the authentication of arbitrary users for requests that modify data or cause a denial of service.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens SIMATIC PCS 7 | =8.0 | |
Siemens WinCC | <=7.0 | |
Siemens WinCC | =5.0 | |
Siemens WinCC | =5.0-sp1 | |
Siemens WinCC | =6.0 | |
Siemens WinCC | =6.0-sp2 | |
Siemens WinCC | =6.0-sp3 | |
Siemens WinCC | =6.0-sp4 | |
Siemens WinCC | =7.0 | |
Siemens WinCC | =7.0-sp1 | |
Siemens WinCC | =7.0-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3028 is rated as a high-severity vulnerability due to its potential for unauthorized data modification and denial of service.
To fix CVE-2012-3028, it is recommended to apply the latest security patches provided by Siemens for affected products.
CVE-2012-3028 affects Siemens WinCC version 7.0 SP3 and earlier, as well as SIMATIC PCS7 and related products.
CVE-2012-3028 is a cross-site request forgery (CSRF) vulnerability that allows attackers to hijack user authentication.
Yes, CVE-2012-3028 can potentially result in unauthorized data modifications, leading to data loss.