CVE-2013-0667: XSS
Published Mar 21, 2013
·Updated
Cross-site scripting (XSS) vulnerability in the HMI web application in Siemens WinCC (TIA Portal) 11 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Affected Software
1 affected component
Siemens Wincc Tia Portal=11.0
Event History
Mar 21, 2013
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-0667?
CVE-2013-0667 has a medium severity rating due to its ability to allow remote attackers to inject arbitrary scripts through XSS.
2
How do I fix CVE-2013-0667?
To fix CVE-2013-0667, upgrade to a version of Siemens WinCC that has patched this vulnerability.
3
Can CVE-2013-0667 be exploited remotely?
Yes, CVE-2013-0667 can be exploited remotely through crafted URLs.
4
Which version of Siemens WinCC is affected by CVE-2013-0667?
CVE-2013-0667 specifically affects Siemens WinCC TIA Portal 11.0.
5
What kind of attacks can CVE-2013-0667 facilitate?
CVE-2013-0667 can facilitate cross-site scripting (XSS) attacks, allowing arbitrary script injection.