CVE-2012-2596
published 2012-06-08CVE-2012-2596: The XPath functionality in unspecified web applications in Siemens WinCC 7.0 SP3 before Update 2 does not properly handle special characters in parameters…
PriorityP426medium5.5CVSS 2.0
AVNACLAuSCPIPAN
EPSS
1.50%
71.4th percentile
The XPath functionality in unspecified web applications in Siemens WinCC 7.0 SP3 before Update 2 does not properly handle special characters in parameters, which allows remote authenticated users to read or modify settings via a crafted URL, related to an "XML injection" attack.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | wincc | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8h44-xxg3-9447: The XPath functionality in unspecified web applications in Siemens WinCC 7
ghsa_unreviewed·2022-05-17
CVE-2012-2596 [MEDIUM] CWE-94 GHSA-8h44-xxg3-9447: The XPath functionality in unspecified web applications in Siemens WinCC 7
The XPath functionality in unspecified web applications in Siemens WinCC 7.0 SP3 before Update 2 does not properly handle special characters in parameters, which allows remote authenticated users to read or modify settings via a crafted URL, related to an "XML injection" attack.
CISA ICS
Siemens WinCC Multiple Vulnerabilities
cisa_ics·2014-01-30
Siemens WinCC Multiple Vulnerabilities
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens WinCC Multiple Vulnerabilities
Last RevisedJanuary 30, 2014
Alert CodeICSA-12-158-01
## Overview
Independent researchers Gleb Gritsai, Alexander Zaitsev, Sergey Scherbel, Yuri Goltsev, Dmitry Serebryannikov, Sergey Bobrov, Denis Baranov, Andrey Medov from Positive Technologies have identified multiple vulnerabilities in the Siemens WinCC application. In evaluating these reported vulnerabilities, Siemens identified an additional vulnerability that is included in this advisory. Siemens has produced an update that resolves all vulnerabilities except the buffer overflow in D
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-223158.pdfhttp://www.us-cert.gov/control_systems/pdf/ICSA-12-158-01.pdfhttp://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-223158.pdfhttp://www.us-cert.gov/control_systems/pdf/ICSA-12-158-01.pdf
2012-06-08
Published