CVE-2013-0671: Path Traversal
Published Mar 21, 2013
·Updated
Directory traversal vulnerability in Siemens WinCC (TIA Portal) 11 allows remote authenticated users to read HMI web-application source code and user-defined scripts via a crafted URL.
Affected Software
1 affected component
Siemens Wincc Tia Portal=11.0
Event History
Mar 21, 2013
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-0671?
CVE-2013-0671 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2013-0671?
To fix CVE-2013-0671, ensure that you apply any security patches provided by Siemens for WinCC (TIA Portal) 11.
3
Who is affected by CVE-2013-0671?
Remote authenticated users of Siemens WinCC (TIA Portal) version 11.0 are affected by CVE-2013-0671.
4
What does CVE-2013-0671 allow attackers to do?
CVE-2013-0671 allows attackers to read HMI web-application source code and user-defined scripts.
5
Is there a workaround for CVE-2013-0671?
There are no specific workarounds documented for CVE-2013-0671; applying patches is recommended.