CVE-2013-4912: Input Validation
Open redirect vulnerability in Siemens WinCC (TIA Portal) 11 and 12 before 12 SP1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks by leveraging improper configuration of SIMATIC HMI panels by the WinCC product.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4912?
CVE-2013-4912 is rated as a high-severity vulnerability due to its potential for facilitating phishing attacks.
How do I fix CVE-2013-4912?
To fix CVE-2013-4912, ensure proper configuration of SIMATIC HMI panels and apply any available patches from Siemens.
Which versions of Siemens WinCC are affected by CVE-2013-4912?
CVE-2013-4912 affects Siemens WinCC versions 11.0, 11.0 SP1, 11.0 SP2, and 12.0.
What kind of attack does CVE-2013-4912 enable?
CVE-2013-4912 enables remote attackers to redirect users to arbitrary web sites, facilitating phishing attacks.
Is user intervention required to exploit CVE-2013-4912?
Yes, user intervention is required as they must be redirected through a manipulated link to trigger the vulnerability.