CVE-2013-4912Improper Input Validation in Siemens Wincc

Severity
5.8MEDIUMNVD
EPSS
0.5%
top 32.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 1
Latest updateMay 17

Description

Open redirect vulnerability in Siemens WinCC (TIA Portal) 11 and 12 before 12 SP1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks by leveraging improper configuration of SIMATIC HMI panels by the WinCC product.

CVSS vector

AV:N/AC:M/C:P/I:P/A:NExploitability: 8.6 | Impact: 4.9

Affected Packages1 packages

NVDsiemens/wincc11.0, 12.0+1

🔴Vulnerability Details

2
GHSA
GHSA-fj47-554h-3xpr: Open redirect vulnerability in Siemens WinCC (TIA Portal) 11 and 12 before 12 SP1 allows remote attackers to redirect users to arbitrary web sites and2022-05-17
CVEList
CVE-2013-4912: Open redirect vulnerability in Siemens WinCC (TIA Portal) 11 and 12 before 12 SP1 allows remote attackers to redirect users to arbitrary web sites and2013-07-31
CVE-2013-4912 — Improper Input Validation in Siemens | cvebase