PT-2012-1980 · Siemens · Wincc V11 Runtime Advanced+9

Luigi Auriemma

·

Publicado

2012-02-03

·

Atualizado

2017-08-29

·

CVE-2011-4877

CVSS v2.0

7.1

Alta

VetorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Siemens WinCC flexible versions 2004 through 2008 WinCC V11 (aka TIA portal) TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels WinCC V11 Runtime Advanced WinCC flexible Runtime
Description The issue allows remote attackers to cause a denial of service, resulting in an application crash, by sending crafted data over TCP when Transfer Mode is enabled.
Recommendations For Siemens WinCC flexible versions 2004 through 2008, disable Transfer Mode to prevent exploitation. For WinCC V11 (aka TIA portal), disable Transfer Mode to prevent exploitation. For TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels, disable Transfer Mode to prevent exploitation. For WinCC V11 Runtime Advanced, disable Transfer Mode to prevent exploitation. For WinCC flexible Runtime, disable Transfer Mode to prevent exploitation.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-4877

Produtos afetados

Comfort Panels
Mp
Mobile Panels
Op
Simatic Hmi Panels
Tp
Wincc V11
Wincc V11 Runtime Advanced
Wincc Flexible
Wincc Flexible Runtime