Siemens Wincc vulnerabilities
43 known vulnerabilities affecting siemens/wincc.
Total CVEs
43
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH8MEDIUM29
Vulnerabilities
Page 2 of 3
CVE-2012-3030P4MEDIUMCVSS 5.0≤ 7.0v5.0+2 more2012-09-18
CVE-2012-3030 [MEDIUM] CWE-264 CVE-2012-3030: WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, store
WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, stores sensitive information under the web root with insufficient access control, which allows remote attackers to read a (1) log file or (2) configuration file via a direct request.
nvd
CVE-2012-3028P4MEDIUMCVSS 6.8≤ 7.0v5.0+2 more2012-09-18
CVE-2012-3028 [MEDIUM] CWE-352 CVE-2012-3028: Cross-site request forgery (CSRF) vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier
Cross-site request forgery (CSRF) vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to hijack the authentication of arbitrary users for requests that modify data or cause a denial of service.
nvd
CVE-2013-4912P4MEDIUMCVSS 5.8v11.0v12.02013-08-01
CVE-2013-4912 [MEDIUM] CWE-20 CVE-2013-4912: Open redirect vulnerability in Siemens WinCC (TIA Portal) 11 and 12 before 12 SP1 allows remote atta
Open redirect vulnerability in Siemens WinCC (TIA Portal) 11 and 12 before 12 SP1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks by leveraging improper configuration of SIMATIC HMI panels by the WinCC product.
nvd
CVE-2012-2596P4MEDIUMCVSS 5.5v7.02012-06-08
CVE-2012-2596 [MEDIUM] CWE-94 CVE-2012-2596: The XPath functionality in unspecified web applications in Siemens WinCC 7.0 SP3 before Update 2 doe
The XPath functionality in unspecified web applications in Siemens WinCC 7.0 SP3 before Update 2 does not properly handle special characters in parameters, which allows remote authenticated users to read or modify settings via a crafted URL, related to an "XML injection" attack.
nvd
CVE-2014-4683P4MEDIUMCVSS 4.9≤ 7.2v5.0+3 more2014-07-24
CVE-2014-4683 [MEDIUM] CWE-264 CVE-2014-4683: The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, all
The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote authenticated users to gain privileges via a (1) HTTP or (2) HTTPS request.
nvd
CVE-2011-4512P4MEDIUMCVSS 5.0≤ v11vv112012-02-03
CVE-2011-4512 [MEDIUM] CWE-94 CVE-2011-4512: CRLF injection vulnerability in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2
CRLF injection vulnerability in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime allows remote attackers to inject arbitrary HTTP headers and cond
nvd
CVE-2012-3034P4MEDIUMCVSS 4.3≤ 7.0v5.0+2 more2012-09-18
CVE-2012-3034 [MEDIUM] CWE-200 CVE-2012-3034: WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allow
WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to discover a username and password via crafted parameters to unspecified methods in ActiveX controls.
nvd
CVE-2013-0677P4MEDIUMCVSS 5.8≤ 7.1v5.0+2 more2013-03-21
CVE-2013-0677 [MEDIUM] CWE-200 CVE-2013-0677: The web server in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other product
The web server in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, allows remote attackers to obtain sensitive information or cause a denial of service via a crafted project file.
nvd
CVE-2013-0679P4MEDIUMCVSS 4.0≤ 7.1v5.0+2 more2013-03-21
CVE-2013-0679 [MEDIUM] CWE-22 CVE-2013-0679: Directory traversal vulnerability in the web server in Siemens WinCC before 7.2, as used in SIMATIC
Directory traversal vulnerability in the web server in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, allows remote authenticated users to read arbitrary files via vectors involving a query for a pathname.
nvd
CVE-2013-0675P4MEDIUMCVSS 6.1≤ 7.1v5.0+2 more2013-03-21
CVE-2013-0675 [MEDIUM] CWE-119 CVE-2013-0675: Buffer overflow in CCEServer (aka the central communications component) in Siemens WinCC before 7.2,
Buffer overflow in CCEServer (aka the central communications component) in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, allows remote attackers to cause a denial of service via a crafted packet.
nvd
CVE-2012-2597P4MEDIUMCVSS 4.0v7.02012-06-08
CVE-2012-2597 [MEDIUM] CWE-22 CVE-2012-2597: Multiple directory traversal vulnerabilities in Siemens WinCC 7.0 SP3 before Update 2 allow remote a
Multiple directory traversal vulnerabilities in Siemens WinCC 7.0 SP3 before Update 2 allow remote authenticated users to read arbitrary files via a crafted parameter in a URL.
nvd
CVE-2012-3003P4MEDIUMCVSS 5.8v7.02012-06-08
CVE-2012-3003 [MEDIUM] CWE-20 CVE-2012-3003: Open redirect vulnerability in an unspecified web application in Siemens WinCC 7.0 SP3 before Update
Open redirect vulnerability in an unspecified web application in Siemens WinCC 7.0 SP3 before Update 2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a GET request.
nvd
CVE-2014-4682P4MEDIUMCVSS 5.0≤ 7.2v5.0+3 more2014-07-24
CVE-2014-4682 [MEDIUM] CWE-200 CVE-2014-4682: The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, all
The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote attackers to obtain sensitive information via an HTTP request.
nvd
CVE-2012-2598P4MEDIUMCVSS 4.3v7.02012-06-08
CVE-2012-2598 [MEDIUM] CWE-119 CVE-2012-2598: Buffer overflow in the DiagAgent web server in Siemens WinCC 7.0 SP3 through Update 2 allows remote
Buffer overflow in the DiagAgent web server in Siemens WinCC 7.0 SP3 through Update 2 allows remote attackers to cause a denial of service (agent outage) via crafted input.
nvd
CVE-2015-2822P4MEDIUMCVSS 4.3≤ 13.02015-04-08
CVE-2015-2822 [MEDIUM] CWE-20 CVE-2015-2822: Siemens SIMATIC HMI Comfort Panels before WinCC (TIA Portal) 13 SP1 Upd2 and SIMATIC WinCC Runtime A
Siemens SIMATIC HMI Comfort Panels before WinCC (TIA Portal) 13 SP1 Upd2 and SIMATIC WinCC Runtime Advanced before WinCC (TIA Portal) 13 SP1 Upd2 allow man-in-the-middle attackers to cause a denial of service via crafted packets on TCP port 102.
nvd
CVE-2011-4510P4MEDIUMCVSS 4.3≤ v11vv112012-02-03
CVE-2011-4510 [MEDIUM] CWE-79 CVE-2011-4510: Cross-site scripting (XSS) vulnerability in the HMI web server in Siemens WinCC flexible 2004, 2005,
Cross-site scripting (XSS) vulnerability in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime allows remote attackers to inject arbitrary web scrip
nvd
CVE-2011-4511P4MEDIUMCVSS 4.3≤ v11vv112012-02-03
CVE-2011-4511 [MEDIUM] CVE-2011-4511: Cross-site scripting (XSS) vulnerability in the HMI web server in Siemens WinCC flexible 2004, 2005,
Cross-site scripting (XSS) vulnerability in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime allows remote attackers to inject arbitrary web script or HT
nvd
CVE-2012-2595P4MEDIUMCVSS 4.3v7.02012-06-08
CVE-2012-2595 [MEDIUM] CWE-79 CVE-2012-2595: Multiple cross-site scripting (XSS) vulnerabilities in unspecified web applications in Siemens WinCC
Multiple cross-site scripting (XSS) vulnerabilities in unspecified web applications in Siemens WinCC 7.0 SP3 before Update 2 allow remote attackers to inject arbitrary web script or HTML via vectors involving special characters in parameters.
nvd
CVE-2013-0676P4MEDIUMCVSS 4.0≤ 7.1v5.0+2 more2013-03-21
CVE-2013-0676 [MEDIUM] CWE-264 CVE-2013-0676: Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, does not proper
Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, does not properly assign privileges for the database containing WebNavigator credentials, which allows remote authenticated users to obtain sensitive information via a SQL query.
nvd
CVE-2013-0678P4MEDIUMCVSS 4.0≤ 7.0v7.02013-03-21
CVE-2013-0678 [MEDIUM] CWE-255 CVE-2013-0678: Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, does not proper
Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, does not properly represent WebNavigator credentials in a database, which makes it easier for remote authenticated users to obtain sensitive information via a SQL query.
nvd