CVE-2013-3959: Infoleak
The Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, exhibits different behavior for NetBIOS user names depending on whether the user account exists, which allows remote authenticated users to enumerate account names via crafted URL parameters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3959?
CVE-2013-3959 is categorized as a medium severity vulnerability.
How do I fix CVE-2013-3959?
To remediate CVE-2013-3959, upgrade to Siemens WinCC version 7.2 Update 1 or later.
What types of user accounts are affected by CVE-2013-3959?
CVE-2013-3959 affects authenticated user accounts in Siemens WinCC and SIMATIC PCS7.
Can CVE-2013-3959 lead to remote exploitation?
Yes, CVE-2013-3959 allows remote authenticated users to enumerate account names, which can lead to further exploitation.
What products are affected by CVE-2013-3959?
CVE-2013-3959 affects Siemens WinCC versions 7.0 to 7.2 and SIMATIC PCS7 versions 8.0 SP1 and earlier.