First published: Fri Jun 14 2013(Updated: )
The Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, exhibits different behavior for NetBIOS user names depending on whether the user account exists, which allows remote authenticated users to enumerate account names via crafted URL parameters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens SIMATIC PCS 7 | <=8.0 | |
Siemens SIMATIC PCS 7 | =8.0 | |
Siemens WinCC | <=7.2 | |
Siemens WinCC | =7.0 | |
Siemens WinCC | =7.0-sp1 | |
Siemens WinCC | =7.0-sp2 | |
Siemens WinCC | =7.0-sp3 | |
Siemens WinCC | =7.1 | |
Siemens WinCC | =7.1-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3959 is categorized as a medium severity vulnerability.
To remediate CVE-2013-3959, upgrade to Siemens WinCC version 7.2 Update 1 or later.
CVE-2013-3959 affects authenticated user accounts in Siemens WinCC and SIMATIC PCS7.
Yes, CVE-2013-3959 allows remote authenticated users to enumerate account names, which can lead to further exploitation.
CVE-2013-3959 affects Siemens WinCC versions 7.0 to 7.2 and SIMATIC PCS7 versions 8.0 SP1 and earlier.