CVE-2013-0674

Buffer overflow in the RegReader ActiveX control in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, allows remote attackers to execute arbitrary code via a long parameter.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:siemens:simatic_pcs7:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:simatic_pcs7:7.1:sp3:*:*:*:*:*:*
cpe:2.3:a:siemens:wincc:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:wincc:5.0:*:*:*:*:*:*:*
cpe:2.3:a:siemens:wincc:5.0:sp1:*:*:*:*:*:*
cpe:2.3:a:siemens:wincc:6.0:*:*:*:*:*:*:*
cpe:2.3:a:siemens:wincc:6.0:sp2:*:*:*:*:*:*
cpe:2.3:a:siemens:wincc:6.0:sp3:*:*:*:*:*:*
cpe:2.3:a:siemens:wincc:6.0:sp4:*:*:*:*:*:*
cpe:2.3:a:siemens:wincc:7.0:*:*:*:*:*:*:*
cpe:2.3:a:siemens:wincc:7.0:sp1:*:*:*:*:*:*
cpe:2.3:a:siemens:wincc:7.0:sp2:*:*:*:*:*:*
cpe:2.3:a:siemens:wincc:7.0:sp3:*:*:*:*:*:*

History

21 Nov 2024, 01:47

Type Values Removed Values Added
References () http://ics-cert.us-cert.gov/pdf/ICSA-13-079-02.pdf - US Government Resource () http://ics-cert.us-cert.gov/pdf/ICSA-13-079-02.pdf - US Government Resource
References () http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-714398.pdf - Vendor Advisory () http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-714398.pdf - Vendor Advisory

Information

Published : 2013-03-21 15:55

Updated : 2024-11-21 01:47


NVD link : CVE-2013-0674

Mitre link : CVE-2013-0674

CVE.ORG link : CVE-2013-0674


JSON object : View

Products Affected

siemens

  • wincc
  • simatic_pcs7
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer