CVE-2012-3028

Cross-site request forgery (CSRF) vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to hijack the authentication of arbitrary users for requests that modify data or cause a denial of service.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:siemens:simatic_pcs7:8.0:*:*:*:*:*:*:*
cpe:2.3:a:siemens:wincc:*:sp3:*:*:*:*:*:*
cpe:2.3:a:siemens:wincc:5.0:*:*:*:*:*:*:*
cpe:2.3:a:siemens:wincc:5.0:sp1:*:*:*:*:*:*
cpe:2.3:a:siemens:wincc:6.0:*:*:*:*:*:*:*
cpe:2.3:a:siemens:wincc:6.0:sp2:*:*:*:*:*:*
cpe:2.3:a:siemens:wincc:6.0:sp3:*:*:*:*:*:*
cpe:2.3:a:siemens:wincc:6.0:sp4:*:*:*:*:*:*
cpe:2.3:a:siemens:wincc:7.0:*:*:*:*:*:*:*
cpe:2.3:a:siemens:wincc:7.0:sp1:*:*:*:*:*:*
cpe:2.3:a:siemens:wincc:7.0:sp2:*:*:*:*:*:*

History

21 Nov 2024, 01:40

Type Values Removed Values Added
References () http://en.securitylab.ru/lab/PT-2012-42 - () http://en.securitylab.ru/lab/PT-2012-42 -
References () http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-864051.pdf - Patch () http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-864051.pdf - Patch
References () http://www.us-cert.gov/control_systems/pdf/ICSA-12-256-01.pdf - () http://www.us-cert.gov/control_systems/pdf/ICSA-12-256-01.pdf -

Information

Published : 2012-09-18 14:55

Updated : 2024-11-21 01:40


NVD link : CVE-2012-3028

Mitre link : CVE-2012-3028

CVE.ORG link : CVE-2012-3028


JSON object : View

Products Affected

siemens

  • wincc
  • simatic_pcs7
CWE
CWE-352

Cross-Site Request Forgery (CSRF)