7.5

CVE-2013-3958

The login implementation in the Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, has a hardcoded account, which makes it easier for remote attackers to obtain access via an unspecified request.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Siemens ≫ Simatic Pcs7 Update sp1 Version <= 8.0
Siemens ≫ Simatic Pcs7 Version 8.0
Siemens ≫ Wincc Version <= 7.2
Siemens ≫ Wincc Version 7.0
Siemens ≫ Wincc Version 7.0 Update sp1
Siemens ≫ Wincc Version 7.0 Update sp2
Siemens ≫ Wincc Version 7.0 Update sp3
Siemens ≫ Wincc Version 7.1
Siemens ≫ Wincc Version 7.1 Update sp1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.93% 0.774
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-345843.pdf
Vendor Advisory