First published: Thu Mar 21 2013(Updated: )
Cross-site scripting (XSS) vulnerability in the HMI web application in Siemens WinCC (TIA Portal) 11 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens TIA Portal | =11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0667 has a medium severity rating due to its ability to allow remote attackers to inject arbitrary scripts through XSS.
To fix CVE-2013-0667, upgrade to a version of Siemens WinCC that has patched this vulnerability.
Yes, CVE-2013-0667 can be exploited remotely through crafted URLs.
CVE-2013-0667 specifically affects Siemens WinCC TIA Portal 11.0.
CVE-2013-0667 can facilitate cross-site scripting (XSS) attacks, allowing arbitrary script injection.