CVE-2012-3030: Medium severity Siemens SIMATIC PCS7 vulnerability
WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, stores sensitive information under the web root with insufficient access control, which allows remote attackers to read a (1) log file or (2) configuration file via a direct request.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3030?
CVE-2012-3030 is considered to be a high severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2012-3030?
To fix CVE-2012-3030, implement proper access controls to sensitive files stored under the web root in Siemens WinCC.
What types of files are vulnerable in CVE-2012-3030?
CVE-2012-3030 allows remote attackers to read log files and configuration files due to insufficient access control.
Which versions of Siemens software are affected by CVE-2012-3030?
CVE-2012-3030 affects Siemens WinCC versions up to 7.0 SP3 and earlier, including specific versions of SIMATIC PCS7.
Can CVE-2012-3030 lead to data breaches?
Yes, CVE-2012-3030 can potentially allow attackers to access sensitive information, leading to data breaches.