PT-2012-4451 · Siemens · Webnavigator+2

Denis Baranov

+1

·

Published

2012-09-18

·

Updated

2012-09-19

·

CVE-2012-3032

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Siemens WinCC versions 7.0 SP3 and earlier
Description A SQL injection issue allows remote attackers to execute arbitrary SQL commands via a crafted SOAP message. This affects products that use WebNavigator in Siemens WinCC, such as SIMATIC PCS7.
Recommendations For versions 7.0 SP3 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-3032

Affected Products

Simatic Pcs7
Siemens Wincc
Webnavigator