First published: Fri Jun 14 2013(Updated: )
SQL injection vulnerability in the login screen in the Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens SIMATIC PCS 7 | <=8.0 | |
Siemens SIMATIC PCS 7 | =8.0 | |
Siemens WinCC | <=7.2 | |
Siemens WinCC | =7.0 | |
Siemens WinCC | =7.0-sp1 | |
Siemens WinCC | =7.0-sp2 | |
Siemens WinCC | =7.0-sp3 | |
Siemens WinCC | =7.1 | |
Siemens WinCC | =7.1-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3957 is classified as a high-severity vulnerability due to its potential for remote SQL command execution.
To fix CVE-2013-3957, upgrade to Siemens WinCC version 7.2 Update 1 or later, or to a version of SIMATIC PCS7 that is not vulnerable.
CVE-2013-3957 affects Siemens WinCC versions up to 7.2 and SIMATIC PCS7 versions 8.0 SP1 and earlier.
Yes, CVE-2013-3957 can be exploited remotely by attackers to execute arbitrary SQL commands.
CVE-2013-3957 is an SQL injection vulnerability found in the login screen of Siemens WinCC.