CVE-2012-3030
Published Sep 18, 2012
Last updated 12 years ago
Overview
- Description
- WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, stores sensitive information under the web root with insufficient access control, which allows remote attackers to read a (1) log file or (2) configuration file via a direct request.
- Source
- ics-cert@hq.dhs.gov
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:siemens:simatic_pcs7:8.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E8B894F4-9635-4436-BC0A-E43280426017" }, { "criteria": "cpe:2.3:a:siemens:wincc:*:sp3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5AC094B0-B1BE-436D-A8D3-2008D0CDE070", "versionEndIncluding": "7.0" }, { "criteria": "cpe:2.3:a:siemens:wincc:5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B4CB277F-7ECB-4F44-8BB5-A3D350486EE7" }, { "criteria": "cpe:2.3:a:siemens:wincc:5.0:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "616535F1-F609-408B-AE48-61ACF48748A1" }, { "criteria": "cpe:2.3:a:siemens:wincc:6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7F322FCB-32F4-4C5A-A7F5-F7EF41188C88" }, { "criteria": "cpe:2.3:a:siemens:wincc:6.0:sp2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "69822DB4-DC79-4F88-A470-5AC512C77377" }, { "criteria": "cpe:2.3:a:siemens:wincc:6.0:sp3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "996DE8BD-DD51-41EF-9882-C2BD2CC5FE53" }, { "criteria": "cpe:2.3:a:siemens:wincc:6.0:sp4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "945C8B46-4CDA-4143-889C-30E30E93DB29" }, { "criteria": "cpe:2.3:a:siemens:wincc:7.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A33F9015-7058-419A-8762-CB2AE4ACF1A7" }, { "criteria": "cpe:2.3:a:siemens:wincc:7.0:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E6271FCC-CCF6-4D31-801A-B4B0DC4639DD" }, { "criteria": "cpe:2.3:a:siemens:wincc:7.0:sp2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DF7A6B2B-D573-4285-B3B4-136F2BE7E710" } ], "operator": "OR" } ] } ]