CVE-2013-0679
 
Severity Score
4.0
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Directory traversal vulnerability in the web server in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, allows remote authenticated users to read arbitrary files via vectors involving a query for a pathname.
Vulnerabilidad de salto de directorio en el servidor web en Siemens WinCC anterior a v7.2, como se usa en SIMATIC PCS7 anterior a v8.0 SP1 y otros productos, permite a usuarios remotamente autenticados leer ficheros a través de vectores que implican una consulta al pathname.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2012-12-19 CVE Reserved
- 2013-03-21 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://ics-cert.us-cert.gov/pdf/ICSA-13-079-02.pdf | Us Government Resource |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Siemens Search vendor "Siemens" | Simatic Pcs7 Search vendor "Siemens" for product "Simatic Pcs7" | <= 8.0 Search vendor "Siemens" for product "Simatic Pcs7" and version " <= 8.0" | - |
Affected
| ||||||
Siemens Search vendor "Siemens" | Simatic Pcs7 Search vendor "Siemens" for product "Simatic Pcs7" | 7.1 Search vendor "Siemens" for product "Simatic Pcs7" and version "7.1" | sp3 |
Affected
| ||||||
Siemens Search vendor "Siemens" | Wincc Search vendor "Siemens" for product "Wincc" | <= 7.1 Search vendor "Siemens" for product "Wincc" and version " <= 7.1" | - |
Affected
| ||||||
Siemens Search vendor "Siemens" | Wincc Search vendor "Siemens" for product "Wincc" | 5.0 Search vendor "Siemens" for product "Wincc" and version "5.0" | - |
Affected
| ||||||
Siemens Search vendor "Siemens" | Wincc Search vendor "Siemens" for product "Wincc" | 5.0 Search vendor "Siemens" for product "Wincc" and version "5.0" | sp1 |
Affected
| ||||||
Siemens Search vendor "Siemens" | Wincc Search vendor "Siemens" for product "Wincc" | 6.0 Search vendor "Siemens" for product "Wincc" and version "6.0" | - |
Affected
| ||||||
Siemens Search vendor "Siemens" | Wincc Search vendor "Siemens" for product "Wincc" | 6.0 Search vendor "Siemens" for product "Wincc" and version "6.0" | sp2 |
Affected
| ||||||
Siemens Search vendor "Siemens" | Wincc Search vendor "Siemens" for product "Wincc" | 6.0 Search vendor "Siemens" for product "Wincc" and version "6.0" | sp3 |
Affected
| ||||||
Siemens Search vendor "Siemens" | Wincc Search vendor "Siemens" for product "Wincc" | 6.0 Search vendor "Siemens" for product "Wincc" and version "6.0" | sp4 |
Affected
| ||||||
Siemens Search vendor "Siemens" | Wincc Search vendor "Siemens" for product "Wincc" | 7.0 Search vendor "Siemens" for product "Wincc" and version "7.0" | - |
Affected
| ||||||
Siemens Search vendor "Siemens" | Wincc Search vendor "Siemens" for product "Wincc" | 7.0 Search vendor "Siemens" for product "Wincc" and version "7.0" | sp1 |
Affected
| ||||||
Siemens Search vendor "Siemens" | Wincc Search vendor "Siemens" for product "Wincc" | 7.0 Search vendor "Siemens" for product "Wincc" and version "7.0" | sp2 |
Affected
| ||||||
Siemens Search vendor "Siemens" | Wincc Search vendor "Siemens" for product "Wincc" | 7.0 Search vendor "Siemens" for product "Wincc" and version "7.0" | sp3 |
Affected
|