Lucene search

K
nvd[email protected]NVD:CVE-2013-4912
HistoryAug 01, 2013 - 1:32 p.m.

CVE-2013-4912

2013-08-0113:32:26
CWE-20
web.nvd.nist.gov
6

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

AI Score

6.7

Confidence

Low

EPSS

0.004

Percentile

73.2%

Open redirect vulnerability in Siemens WinCC (TIA Portal) 11 and 12 before 12 SP1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks by leveraging improper configuration of SIMATIC HMI panels by the WinCC product.

Affected configurations

Nvd
Node
siemenswinccMatch11.0
OR
siemenswinccMatch11.0sp1
OR
siemenswinccMatch11.0sp2
OR
siemenswinccMatch12.0
VendorProductVersionCPE
siemenswincc11.0cpe:2.3:a:siemens:wincc:11.0:*:*:*:*:*:*:*
siemenswincc11.0cpe:2.3:a:siemens:wincc:11.0:sp1:*:*:*:*:*:*
siemenswincc11.0cpe:2.3:a:siemens:wincc:11.0:sp2:*:*:*:*:*:*
siemenswincc12.0cpe:2.3:a:siemens:wincc:12.0:*:*:*:*:*:*:*

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

AI Score

6.7

Confidence

Low

EPSS

0.004

Percentile

73.2%

Related for NVD:CVE-2013-4912