CVE-2013-3958
Last modified
CVE-2013-3958 is a vulnerability of currently unknown severity. The login implementation in the Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, has a hardcoded account, which makes it easier for remote attackers to obtain access via an unspecified request.. EPSS estimates a 1.93% chance of exploitation in the next 30 days.
Description
The login implementation in the Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, has a hardcoded account, which makes it easier for remote attackers to obtain access via an unspecified request.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Siemens | Simatic Pcs7 | <= 8.0 | Sp1 |
| Siemens | Simatic Pcs7 | 8.0 | — |
| Siemens | Wincc | <= 7.2 | — |
| Siemens | Wincc | 7.0 | — |
| Siemens | Wincc | 7.1 | — |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-3958?
How severe is CVE-2013-3958?
How do I fix CVE-2013-3958?
Are you affected by CVE-2013-3958?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
