First published: Tue Sep 18 2012(Updated: )
WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to discover a username and password via crafted parameters to unspecified methods in ActiveX controls.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens SIMATIC PCS 7 | =8.0 | |
Siemens WinCC | <=7.0 | |
Siemens WinCC | =5.0 | |
Siemens WinCC | =5.0-sp1 | |
Siemens WinCC | =6.0 | |
Siemens WinCC | =6.0-sp2 | |
Siemens WinCC | =6.0-sp3 | |
Siemens WinCC | =6.0-sp4 | |
Siemens WinCC | =7.0 | |
Siemens WinCC | =7.0-sp1 | |
Siemens WinCC | =7.0-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3034 is classified as a medium-severity vulnerability due to its potential to allow remote attackers to discover credentials.
To fix CVE-2012-3034, upgrade to a version of Siemens WinCC or SIMATIC PCS7 that is patched against this vulnerability.
CVE-2012-3034 affects Siemens WinCC versions 7.0 SP2 and earlier, as well as lower versions like 6.0 SP4 and earlier.
Yes, CVE-2012-3034 can be exploited by remote attackers who can manipulate parameters in the ActiveX controls.
CVE-2012-3034 impacts Siemens WinCC, as well as SIMATIC PCS7 and other related Siemens products.