CVE-2012-3034: Infoleak
WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to discover a username and password via crafted parameters to unspecified methods in ActiveX controls.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3034?
CVE-2012-3034 is classified as a medium-severity vulnerability due to its potential to allow remote attackers to discover credentials.
How do I fix CVE-2012-3034?
To fix CVE-2012-3034, upgrade to a version of Siemens WinCC or SIMATIC PCS7 that is patched against this vulnerability.
Which versions of Siemens WinCC are affected by CVE-2012-3034?
CVE-2012-3034 affects Siemens WinCC versions 7.0 SP2 and earlier, as well as lower versions like 6.0 SP4 and earlier.
Can CVE-2012-3034 be exploited remotely?
Yes, CVE-2012-3034 can be exploited by remote attackers who can manipulate parameters in the ActiveX controls.
What products are impacted by CVE-2012-3034?
CVE-2012-3034 impacts Siemens WinCC, as well as SIMATIC PCS7 and other related Siemens products.