CVE-2013-0676

Siemens WinCC <7.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, does not properly assign privileges for the database containing WebNavigator credentials, which allows remote authenticated users to obtain sensitive information via a SQL query.

References (2)

Core 2

Scores

EPSS 0.0021
EPSS Percentile 43.5%

Details

CWE
CWE-264
Status published
Products (6)
siemens/simatic_pcs7 7.1 sp3
siemens/simatic_pcs7 < 8.0
siemens/wincc 5.0 (2 CPE variants)
siemens/wincc 6.0 (4 CPE variants)
siemens/wincc 7.0 (4 CPE variants)
siemens/wincc < 7.1
Published Mar 21, 2013
Tracked Since Feb 18, 2026