CVE-2013-3959
 
Severity Score
4.0
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, exhibits different behavior for NetBIOS user names depending on whether the user account exists, which allows remote authenticated users to enumerate account names via crafted URL parameters.
El navegador Web de Siemens WinCC antes de v7.2 Update 1, tal y como se utiliza en SIMATIC PCS7 v8.0 SP1 y anteriores y otros productos, muestra un comportamiento diferente para los nombres de usuario de NetBIOS en función de si existe o no la cuenta de usuario, lo que permite a usuarios remotos autenticados enumerar nombres de cuenta a través de parámetros de la URL modificados a mano.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2013-06-05 CVE Reserved
- 2013-06-14 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Siemens Search vendor "Siemens" | Simatic Pcs7 Search vendor "Siemens" for product "Simatic Pcs7" | <= 8.0 Search vendor "Siemens" for product "Simatic Pcs7" and version " <= 8.0" | sp1 |
Affected
| ||||||
Siemens Search vendor "Siemens" | Simatic Pcs7 Search vendor "Siemens" for product "Simatic Pcs7" | 8.0 Search vendor "Siemens" for product "Simatic Pcs7" and version "8.0" | - |
Affected
| ||||||
Siemens Search vendor "Siemens" | Wincc Search vendor "Siemens" for product "Wincc" | <= 7.2 Search vendor "Siemens" for product "Wincc" and version " <= 7.2" | - |
Affected
| ||||||
Siemens Search vendor "Siemens" | Wincc Search vendor "Siemens" for product "Wincc" | 7.0 Search vendor "Siemens" for product "Wincc" and version "7.0" | - |
Affected
| ||||||
Siemens Search vendor "Siemens" | Wincc Search vendor "Siemens" for product "Wincc" | 7.0 Search vendor "Siemens" for product "Wincc" and version "7.0" | sp1 |
Affected
| ||||||
Siemens Search vendor "Siemens" | Wincc Search vendor "Siemens" for product "Wincc" | 7.0 Search vendor "Siemens" for product "Wincc" and version "7.0" | sp2 |
Affected
| ||||||
Siemens Search vendor "Siemens" | Wincc Search vendor "Siemens" for product "Wincc" | 7.0 Search vendor "Siemens" for product "Wincc" and version "7.0" | sp3 |
Affected
| ||||||
Siemens Search vendor "Siemens" | Wincc Search vendor "Siemens" for product "Wincc" | 7.1 Search vendor "Siemens" for product "Wincc" and version "7.1" | - |
Affected
| ||||||
Siemens Search vendor "Siemens" | Wincc Search vendor "Siemens" for product "Wincc" | 7.1 Search vendor "Siemens" for product "Wincc" and version "7.1" | sp1 |
Affected
|