PT-2012-1980 · Siemens · Wincc V11 Runtime Advanced+9
Luigi Auriemma
·
Publicado
2012-02-03
·
Atualizado
2017-08-29
·
CVE-2011-4877
CVSS v2.0
7.1
Alta
| Vetor | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Siemens WinCC flexible versions 2004 through 2008
WinCC V11 (aka TIA portal)
TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels
WinCC V11 Runtime Advanced
WinCC flexible Runtime
Description
The issue allows remote attackers to cause a denial of service, resulting in an application crash, by sending crafted data over TCP when Transfer Mode is enabled.
Recommendations
For Siemens WinCC flexible versions 2004 through 2008, disable Transfer Mode to prevent exploitation.
For WinCC V11 (aka TIA portal), disable Transfer Mode to prevent exploitation.
For TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels, disable Transfer Mode to prevent exploitation.
For WinCC V11 Runtime Advanced, disable Transfer Mode to prevent exploitation.
For WinCC flexible Runtime, disable Transfer Mode to prevent exploitation.
Exploit
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Comfort Panels
Mp
Mobile Panels
Op
Simatic Hmi Panels
Tp
Wincc V11
Wincc V11 Runtime Advanced
Wincc Flexible
Wincc Flexible Runtime