CVE-2013-0676: Medium severity Siemens SIMATIC PCS7 vulnerability
Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, does not properly assign privileges for the database containing WebNavigator credentials, which allows remote authenticated users to obtain sensitive information via a SQL query.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0676?
CVE-2013-0676 has a medium severity rating due to improper privilege assignment for accessing sensitive database information.
How do I fix CVE-2013-0676?
To fix CVE-2013-0676, update Siemens WinCC and SIMATIC PCS 7 to the latest patched versions that address this vulnerability.
Who is affected by CVE-2013-0676?
CVE-2013-0676 affects users of Siemens WinCC versions before 7.2 and SIMATIC PCS 7 versions before 8.0 SP1.
What type of attack can exploit CVE-2013-0676?
CVE-2013-0676 can be exploited by remote authenticated users to execute SQL queries and potentially obtain sensitive information.
Is there a workaround for CVE-2013-0676?
As a workaround for CVE-2013-0676, limit remote access and database permissions until an update can be applied.