First published: Tue Sep 18 2012(Updated: )
WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, stores sensitive information under the web root with insufficient access control, which allows remote attackers to read a (1) log file or (2) configuration file via a direct request.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Simatic PCS 7 | =8.0 | |
Siemens WinCC | <=7.0 | |
Siemens WinCC | =5.0 | |
Siemens WinCC | =5.0-sp1 | |
Siemens WinCC | =6.0 | |
Siemens WinCC | =6.0-sp2 | |
Siemens WinCC | =6.0-sp3 | |
Siemens WinCC | =6.0-sp4 | |
Siemens WinCC | =7.0 | |
Siemens WinCC | =7.0-sp1 | |
Siemens WinCC | =7.0-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3030 is considered to be a high severity vulnerability due to the potential exposure of sensitive information.
To fix CVE-2012-3030, implement proper access controls to sensitive files stored under the web root in Siemens WinCC.
CVE-2012-3030 allows remote attackers to read log files and configuration files due to insufficient access control.
CVE-2012-3030 affects Siemens WinCC versions up to 7.0 SP3 and earlier, including specific versions of SIMATIC PCS7.
Yes, CVE-2012-3030 can potentially allow attackers to access sensitive information, leading to data breaches.