Lucene search

K
cveMitreCVE-2013-4912
HistoryAug 01, 2013 - 1:32 p.m.

CVE-2013-4912

2013-08-0113:32:26
CWE-20
mitre
web.nvd.nist.gov
27
siemens
wincc
tia portal
open redirect vulnerability
phishing
nvd
cve-2013-4912

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

AI Score

6.9

Confidence

Low

EPSS

0.004

Percentile

73.2%

Open redirect vulnerability in Siemens WinCC (TIA Portal) 11 and 12 before 12 SP1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks by leveraging improper configuration of SIMATIC HMI panels by the WinCC product.

Affected configurations

Nvd
Node
siemenswinccMatch11.0
OR
siemenswinccMatch11.0sp1
OR
siemenswinccMatch11.0sp2
OR
siemenswinccMatch12.0
VendorProductVersionCPE
siemenswincc11.0cpe:2.3:a:siemens:wincc:11.0:*:*:*:*:*:*:*
siemenswincc11.0cpe:2.3:a:siemens:wincc:11.0:sp1:*:*:*:*:*:*
siemenswincc11.0cpe:2.3:a:siemens:wincc:11.0:sp2:*:*:*:*:*:*
siemenswincc12.0cpe:2.3:a:siemens:wincc:12.0:*:*:*:*:*:*:*

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

AI Score

6.9

Confidence

Low

EPSS

0.004

Percentile

73.2%

Related for CVE-2013-4912