CVE-2013-0669: Input Validation
Published Mar 21, 2013
·Updated
The HMI web application in Siemens WinCC (TIA Portal) 11 allows remote authenticated users to cause a denial of service (daemon crash) via a crafted HTTP request.
Affected Software
1 affected component
Siemens Wincc Tia Portal=11.0
Event History
Mar 21, 2013
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-0669?
CVE-2013-0669 has a medium severity rating as it can lead to a denial of service due to daemon crashes.
2
How do I fix CVE-2013-0669?
To fix CVE-2013-0669, ensure you update Siemens WinCC (TIA Portal) to a version beyond 11.0 that addresses this vulnerability.
3
What type of attack does CVE-2013-0669 enable?
CVE-2013-0669 enables a denial of service attack through crafted HTTP requests from remote authenticated users.
4
Which version of Siemens software is affected by CVE-2013-0669?
CVE-2013-0669 affects version 11.0 of Siemens WinCC (TIA Portal).
5
Who can exploit CVE-2013-0669?
CVE-2013-0669 can be exploited by remote authenticated users who can send crafted HTTP requests.