VulnerabilityModified
CVE-2013-0677
The web server in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, allows remote attackers to obtain sensitive information or cause a denial of service via a crafted project file.
MEDIUM 5.8EPSS 1.90%
Does this matter?
Lower severity and a low EPSS score (1.90%). Track it; it rarely justifies an emergency change on its own.
Description
The web server in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, allows remote attackers to obtain sensitive information or cause a denial of service via a crafted project file.
- CVSS 2.0
- 5.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:P
- EPSS
- 1.90% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- siemens/simatic pcs7 · siemens/wincc
- Source
- ics-cert@hq.dhs.gov
References
- http://ics-cert.us-cert.gov/pdf/ICSA-13-079-02.pdfUS Government Resource
- http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-714398.pdfVendor Advisory
- http://ics-cert.us-cert.gov/pdf/ICSA-13-079-02.pdfUS Government Resource
- http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-714398.pdfVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.