SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-3028

Cross-site request forgery (CSRF) vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to hijack the authentication of arbitrary users for requests that modify data or…

MEDIUM 6.8EPSS 0.98%

Does this matter?

Lower severity and a low EPSS score (0.98%). Track it; it rarely justifies an emergency change on its own.

Description

Cross-site request forgery (CSRF) vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to hijack the authentication of arbitrary users for requests that modify data or cause a denial of service.

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
0.98% probability · 60th percentile
CISA KEV
Not listed
Weakness
CWE-352
Affected
siemens/simatic pcs7 · siemens/wincc
Source
ics-cert@hq.dhs.gov

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.