cbcvebase.
CVE-2010-2772
published 2010-07-22

CVE-2010-2772: Siemens Simatic WinCC and PCS 7 SCADA system uses a hard-coded password, which allows local users to access a back-end database and gain privileges, as…

PriorityP278high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
0.55%
42.4th percentile
Siemens Simatic WinCC and PCS 7 SCADA system uses a hard-coded password, which allows local users to access a back-end database and gain privileges, as demonstrated in the wild in July 2010 by the Stuxnet worm, a different vulnerability than CVE-2010-2568.

Affected

7 ranges
VendorProductVersion rangeFixed in
microsoftwindows_server_2008
siemenssimatic_pcs_7
siemenssimatic_pcs_7
siemenssimatic_pcs_7
siemenssimatic_pcs_7
siemenssimatic_wincc
siemenssimatic_wincc

Detection & IOCsextracted from sources · hover to see the quote

  • Snort/VRT rules were released on July 22, 2010 specifically covering CVE-2010-2772 (Siemens WinCC hard-coded SQL credentials exploited by Stuxnet)
  • Reference the VRT rule advisory page for Snort rule SIDs covering CVE-2010-2772 exploitation traffic
  • ·The hard-coded/default SQL server credentials in SIMATIC WinCC cannot be changed or disabled by users in affected versions — exploitation requires no credential knowledge beyond the baked-in defaults
  • ·Vulnerability is remotely exploitable (network-accessible SQL server), not limited to local access despite some descriptions — CVSS v2 base score 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C)
  • ·Exploitation grants full administrative access to the back-end SQL Server database, enabling arbitrary data reads and writes on the target system

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.