CVE-2013-0678: Medium severity siemens simatic pcs 7 vulnerability
Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, does not properly represent WebNavigator credentials in a database, which makes it easier for remote authenticated users to obtain sensitive information via a SQL query.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0678?
CVE-2013-0678 has been classified as a medium severity vulnerability due to its potential impact on sensitive information exposure.
How do I fix CVE-2013-0678?
To fix CVE-2013-0678, upgrade Siemens WinCC to version 7.2 or later and ensure proper database protection measures are in place.
Who is affected by CVE-2013-0678?
CVE-2013-0678 affects users of Siemens WinCC versions prior to 7.2 and SIMATIC PCS7 versions prior to 8.0 SP1.
What kind of attacks can exploit CVE-2013-0678?
CVE-2013-0678 can be exploited by remote authenticated users performing SQL queries to obtain sensitive information.
Is there any mitigation for CVE-2013-0678 if I can't upgrade?
If upgrading is not possible, restricting access to the database and monitoring user queries can help mitigate the risks associated with CVE-2013-0678.