10

CVE-2011-4514

The TELNET daemon in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime does not perform authentication, which makes it easier for remote attackers to obtain access via a TCP session.

Data is provided by the National Vulnerability Database (NVD)
SiemensWincc Flexible Version2004
SiemensWincc Flexible Version2005
SiemensWincc Flexible Version2007
SiemensWincc Flexible Version2008
SiemensWincc Versionv11
SiemensSimatic Hmi Panels Versioncomfort_panels
SiemensSimatic Hmi Panels Versionmobile_panels
SiemensSimatic Hmi Panels Versionmp
SiemensSimatic Hmi Panels Versionop
SiemensSimatic Hmi Panels Versiontp
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.55% 0.653
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.