Lucene search

K
nvd[email protected]NVD:CVE-2013-3959
HistoryJun 14, 2013 - 7:55 p.m.

CVE-2013-3959

2013-06-1419:55:01
CWE-200
web.nvd.nist.gov
6

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

AI Score

6.2

Confidence

Low

EPSS

0.001

Percentile

47.2%

The Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, exhibits different behavior for NetBIOS user names depending on whether the user account exists, which allows remote authenticated users to enumerate account names via crafted URL parameters.

Affected configurations

Nvd
Node
siemenssimatic_pcs7Range8.0sp1
OR
siemenssimatic_pcs7Match8.0
OR
siemenswinccRange7.2
OR
siemenswinccMatch7.0
OR
siemenswinccMatch7.0sp1
OR
siemenswinccMatch7.0sp2
OR
siemenswinccMatch7.0sp3
OR
siemenswinccMatch7.1
OR
siemenswinccMatch7.1sp1
VendorProductVersionCPE
siemenssimatic_pcs7*cpe:2.3:a:siemens:simatic_pcs7:*:sp1:*:*:*:*:*:*
siemenssimatic_pcs78.0cpe:2.3:a:siemens:simatic_pcs7:8.0:*:*:*:*:*:*:*
siemenswincc*cpe:2.3:a:siemens:wincc:*:*:*:*:*:*:*:*
siemenswincc7.0cpe:2.3:a:siemens:wincc:7.0:*:*:*:*:*:*:*
siemenswincc7.0cpe:2.3:a:siemens:wincc:7.0:sp1:*:*:*:*:*:*
siemenswincc7.0cpe:2.3:a:siemens:wincc:7.0:sp2:*:*:*:*:*:*
siemenswincc7.0cpe:2.3:a:siemens:wincc:7.0:sp3:*:*:*:*:*:*
siemenswincc7.1cpe:2.3:a:siemens:wincc:7.1:*:*:*:*:*:*:*
siemenswincc7.1cpe:2.3:a:siemens:wincc:7.1:sp1:*:*:*:*:*:*

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

AI Score

6.2

Confidence

Low

EPSS

0.001

Percentile

47.2%

Related for NVD:CVE-2013-3959