CVE-2012-3028: CSRF
Cross-site request forgery (CSRF) vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to hijack the authentication of arbitrary users for requests that modify data or cause a denial of service.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3028?
CVE-2012-3028 is rated as a high-severity vulnerability due to its potential for unauthorized data modification and denial of service.
How do I fix CVE-2012-3028?
To fix CVE-2012-3028, it is recommended to apply the latest security patches provided by Siemens for affected products.
What products are affected by CVE-2012-3028?
CVE-2012-3028 affects Siemens WinCC version 7.0 SP3 and earlier, as well as SIMATIC PCS7 and related products.
What type of vulnerability is CVE-2012-3028?
CVE-2012-3028 is a cross-site request forgery (CSRF) vulnerability that allows attackers to hijack user authentication.
Can CVE-2012-3028 lead to data loss?
Yes, CVE-2012-3028 can potentially result in unauthorized data modifications, leading to data loss.