CVE-2012-3031: XSS
Multiple cross-site scripting (XSS) vulnerabilities in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allow remote attackers to inject arbitrary web script or HTML via a (1) GET parameter, (2) POST parameter, or (3) Referer HTTP header.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3031?
CVE-2012-3031 is characterized as a medium severity vulnerability due to the potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2012-3031?
To fix CVE-2012-3031, upgrade to Siemens WinCC version 8.0 or later, or apply any available patches provided by Siemens.
What systems are affected by CVE-2012-3031?
CVE-2012-3031 affects Siemens WinCC versions up to 7.0 SP3 and earlier, as well as Siemens Simatic PCS7.
What types of attacks are possible with CVE-2012-3031?
CVE-2012-3031 allows attackers to inject arbitrary web scripts or HTML via GET parameters, POST parameters, or the Referer HTTP header.
Can CVE-2012-3031 be exploited remotely?
Yes, CVE-2012-3031 can be exploited remotely, allowing attackers to execute scripts in the context of the affected web application.