CVE-2013-4911Cross-Site Request Forgery in Siemens Wincc

Severity
6.8MEDIUMNVD
EPSS
0.3%
top 48.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 1
Latest updateMay 17

Description

Cross-site request forgery (CSRF) vulnerability in Siemens WinCC (TIA Portal) 11 and 12 before 12 SP1 allows remote attackers to hijack the authentication of unspecified victims by leveraging improper configuration of SIMATIC HMI panels by the WinCC product.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages1 packages

NVDsiemens/wincc11.0, 12.0+1

🔴Vulnerability Details

2
GHSA
GHSA-prww-5xcf-552x: Cross-site request forgery (CSRF) vulnerability in Siemens WinCC (TIA Portal) 11 and 12 before 12 SP1 allows remote attackers to hijack the authentica2022-05-17
CVEList
CVE-2013-4911: Cross-site request forgery (CSRF) vulnerability in Siemens WinCC (TIA Portal) 11 and 12 before 12 SP1 allows remote attackers to hijack the authentica2013-07-31
CVE-2013-4911 — Cross-Site Request Forgery in Siemens | cvebase