PT-2012-1979 · Siemens · Wincc V11 Runtime Advanced+9

Luigi Auriemma

·

Published

2012-02-03

·

Updated

2017-08-29

·

CVE-2011-4876

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Siemens WinCC flexible versions 2004 through 2008 Siemens WinCC V11 (aka TIA portal) Siemens TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels Siemens WinCC V11 Runtime Advanced Siemens WinCC flexible Runtime
Description The issue allows remote attackers to execute, read, create, modify, or delete arbitrary files via a .. (dot dot) in a string when Transfer Mode is enabled. This is due to a directory traversal vulnerability in HmiLoad in the runtime loader.
Recommendations For Siemens WinCC flexible versions 2004 through 2008, disable Transfer Mode to prevent exploitation. For Siemens WinCC V11 (aka TIA portal), disable Transfer Mode to prevent exploitation. For Siemens TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels, disable Transfer Mode to prevent exploitation. For Siemens WinCC V11 Runtime Advanced, disable Transfer Mode to prevent exploitation. For Siemens WinCC flexible Runtime, disable Transfer Mode to prevent exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-4876

Affected Products

Comfort Panels
Mp
Mobile Panels
Op
Simatic Hmi Panels
Tp
Wincc V11
Wincc V11 Runtime Advanced
Wincc Flexible
Wincc Flexible Runtime