First published: Wed Jul 31 2013(Updated: )
Open redirect vulnerability in Siemens WinCC (TIA Portal) 11 and 12 before 12 SP1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks by leveraging improper configuration of SIMATIC HMI panels by the WinCC product.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens WinCC | =11.0 | |
Siemens WinCC | =11.0-sp1 | |
Siemens WinCC | =11.0-sp2 | |
Siemens WinCC | =12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4912 is rated as a high-severity vulnerability due to its potential for facilitating phishing attacks.
To fix CVE-2013-4912, ensure proper configuration of SIMATIC HMI panels and apply any available patches from Siemens.
CVE-2013-4912 affects Siemens WinCC versions 11.0, 11.0 SP1, 11.0 SP2, and 12.0.
CVE-2013-4912 enables remote attackers to redirect users to arbitrary web sites, facilitating phishing attacks.
Yes, user intervention is required as they must be redirected through a manipulated link to trigger the vulnerability.