CVE-2010-2772
published 2010-07-22CVE-2010-2772: Siemens Simatic WinCC and PCS 7 SCADA system uses a hard-coded password, which allows local users to access a back-end database and gain privileges, as…
PriorityP278high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
0.55%
42.4th percentile
Siemens Simatic WinCC and PCS 7 SCADA system uses a hard-coded password, which allows local users to access a back-end database and gain privileges, as demonstrated in the wild in July 2010 by the Stuxnet worm, a different vulnerability than CVE-2010-2568.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_server_2008 | — | — |
| siemens | simatic_pcs_7 | — | — |
| siemens | simatic_pcs_7 | — | — |
| siemens | simatic_pcs_7 | — | — |
| siemens | simatic_pcs_7 | — | — |
| siemens | simatic_wincc | — | — |
| siemens | simatic_wincc | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Snort/VRT rules were released on July 22, 2010 specifically covering CVE-2010-2772 (Siemens WinCC hard-coded SQL credentials exploited by Stuxnet) ↗
- →Reference the VRT rule advisory page for Snort rule SIDs covering CVE-2010-2772 exploitation traffic ↗
- ·The hard-coded/default SQL server credentials in SIMATIC WinCC cannot be changed or disabled by users in affected versions — exploitation requires no credential knowledge beyond the baked-in defaults ↗
- ·Vulnerability is remotely exploitable (network-accessible SQL server), not limited to local access despite some descriptions — CVSS v2 base score 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C) ↗
- ·Exploitation grants full administrative access to the back-end SQL Server database, enabling arbitrary data reads and writes on the target system ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q89m-g397-f55p: Siemens Simatic WinCC and PCS 7 SCADA system uses a hard-coded password, which allows local users to access a back-end database and gain privileges, a
ghsa_unreviewed·2022-05-17·CVSS 7.8
CVE-2010-2772 [HIGH] CWE-798 GHSA-q89m-g397-f55p: Siemens Simatic WinCC and PCS 7 SCADA system uses a hard-coded password, which allows local users to access a back-end database and gain privileges, a
Siemens Simatic WinCC and PCS 7 SCADA system uses a hard-coded password, which allows local users to access a back-end database and gain privileges, as demonstrated in the wild in July 2010 by the Stuxnet worm, a different vulnerability than CVE-2010-2568.
GHSA
GHSA-6j7w-pxhr-g4pr: Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote atta
ghsa_unreviewed·2022-05-14·CVSS 7.8
CVE-2010-2568 [HIGH] CWE-20 GHSA-6j7w-pxhr-g4pr: Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote atta
Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF shortcut file, which is not properly handled during icon display in Windows Explorer, as demonstrated in the wild in July 2010, and originally reported for malware that leverages CVE-2010-2772 in Siemens WinCC SCADA systems.
VulnCheck
Siemens simatic_wincc Use of Hard-coded Credentials
vulncheck·2010·CVSS 7.8
CVE-2010-2772 [HIGH] Siemens simatic_wincc Use of Hard-coded Credentials
Siemens simatic_wincc Use of Hard-coded Credentials
Siemens Simatic WinCC and PCS 7 SCADA system uses a hard-coded password, which allows local users to access a back-end database and gain privileges, as demonstrated in the wild in July 2010 by the Stuxnet worm, a different vulnerability than CVE-2010-2568.
Affected: Siemens simatic_wincc
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.trendmicro.com/vinfo/us/threat-encyclopedia/web-attack/54/stuxnet-malware-targets-scada-systems; https://support.industry.siemens.com/cs/document/43876783/simatic-wincc-simatic-pcs-7-information-about-malware-viruses-trojan-horses?dti=0&lc=en-US; https://www.wel
CISA ICS
Siemens WinCC Insecure SQL Server Authentication
cisa_ics·2013-05-08
Siemens WinCC Insecure SQL Server Authentication
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens WinCC Insecure SQL Server Authentication
Last RevisedMay 08, 2013
Alert CodeICSA-12-205-01
## Overview
Siemens has released a software update for an insecure SQL server authentication vulnerability in Siemens’ SIMATIC WinCC and SIMATIC PCS 7 software. Previous versions of SIMATIC WinCC use default SQL server credentials that allowed administrative access to the database. The default credentials cannot be changed or disabled. This vulnerability can be remotely exploited, as was the case with Stuxnet malware which was known to target this vulnerability. Siemens has produce
No detection rules found.
No public exploits indexed.
Talos
Rule Release for Today, Thursday July 22nd, 2010
blogs_talos·2010-07-22·CVSS 7.8
CVE-2010-2568 [HIGH] Rule Release for Today, Thursday July 22nd, 2010
Two main vulnerabilities covered in this release. Microsoft Windows Shell shortcut vulnerability (CVE-2010-2568) and the Siemens Simatic WinCC and PCS 7 SCADA vuln (CVE-2010-2772). Both of these are being actively used by the Stuxnet worm.
More details are available here: http://www.snort.org/vrt/advisories/2010/07/22/vrt-rules-2010-07-22.html
Talos
Rule Release for Today, Thursday July 22nd, 2010
blogs_talos·2010-07-22·CVSS 7.8
CVE-2010-2568 [HIGH] Rule Release for Today, Thursday July 22nd, 2010
## Rule Release for Today, Thursday July 22nd, 2010
Two main vulnerabilities covered in this release. Microsoft Windows Shell shortcut vulnerability (CVE-2010-2568) and the Siemens Simatic WinCC and PCS 7 SCADA vuln (CVE-2010-2772). Both of these are being actively used by the Stuxnet worm.
More details are available here: http://www.snort.org/vrt/advisories/2010/07/22/vrt-rules-2010-07-22.html
http://ics-cert.us-cert.gov/advisories/ICSA-12-205-01http://infoworld.com/d/security-central/new-weaponized-virus-targets-industrial-secrets-725http://infoworld.com/d/security-central/siemens-warns-users-dont-change-passwords-after-worm-attack-915?sourcefssrhttp://krebsonsecurity.com/2010/07/experts-warn-of-new-windows-shortcut-flaw/http://secunia.com/advisories/40682http://support.automation.siemens.com/WW/llisapi.dll?func=cslib.csinfo&lang=en&objid=43876783&caller=viewhttp://support.automation.siemens.com/WW/llisapi.dll?func=cslib.csinfo&lang=en&objid=43876783&chttp://www.automation.siemens.com/forum/guests/PostShow.aspx?PostID=16127&16127&Language=en&PageIndex=1http://www.f-secure.com/weblog/archives/00001987.htmlhttp://www.sea.siemens.com/us/News/Industrial/Pages/WinCC_Update.aspxhttp://www.securityfocus.com/bid/41753http://www.vupen.com/english/advisories/2010/1893http://www.wilderssecurity.com/showpost.php?p=1712134&postcount=22http://www.wired.com/threatlevel/2010/07/siemens-scada/https://exchange.xforce.ibmcloud.com/vulnerabilities/60587http://ics-cert.us-cert.gov/advisories/ICSA-12-205-01http://infoworld.com/d/security-central/new-weaponized-virus-targets-industrial-secrets-725http://infoworld.com/d/security-central/siemens-warns-users-dont-change-passwords-after-worm-attack-915?sourcefssrhttp://krebsonsecurity.com/2010/07/experts-warn-of-new-windows-shortcut-flaw/http://secunia.com/advisories/40682http://support.automation.siemens.com/WW/llisapi.dll?func=cslib.csinfo&lang=en&objid=43876783&caller=viewhttp://support.automation.siemens.com/WW/llisapi.dll?func=cslib.csinfo&lang=en&objid=43876783&chttp://www.automation.siemens.com/forum/guests/PostShow.aspx?PostID=16127&16127&Language=en&PageIndex=1http://www.f-secure.com/weblog/archives/00001987.htmlhttp://www.sea.siemens.com/us/News/Industrial/Pages/WinCC_Update.aspxhttp://www.securityfocus.com/bid/41753http://www.vupen.com/english/advisories/2010/1893http://www.wilderssecurity.com/showpost.php?p=1712134&postcount=22http://www.wired.com/threatlevel/2010/07/siemens-scada/https://exchange.xforce.ibmcloud.com/vulnerabilities/60587
2010-07-22
Published
Exploited in the wild