ID

VAR-201903-1631


TITLE

There is a file upload vulnerability in Siemens Wincc v7.3

Trust: 0.6

sources: CNVD: CNVD-2019-07710

DESCRIPTION

Siemens Wincc v7.3 is a process monitoring system. There is a file upload vulnerability in Siemens Wincc v7.3, which can be exploited by an attacker to perform arbitrary programs

Trust: 0.72

sources: CNVD: CNVD-2019-07710 // IVD: 0fbf5a96-66c5-4026-a901-aff2e7ef5d0d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: 0fbf5a96-66c5-4026-a901-aff2e7ef5d0d // CNVD: CNVD-2019-07710

AFFECTED PRODUCTS

vendor:siemensmodel:winccscope:eqversion:v7.3

Trust: 0.8

sources: IVD: 0fbf5a96-66c5-4026-a901-aff2e7ef5d0d // CNVD: CNVD-2019-07710

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2019-07710
value: MEDIUM

Trust: 0.6

IVD: 0fbf5a96-66c5-4026-a901-aff2e7ef5d0d
value: MEDIUM

Trust: 0.2

CNVD: CNVD-2019-07710
severity: MEDIUM
baseScore: 6.0
vectorString: AV:L/AC:H/AU:S/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: HIGH
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 1.5
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: 0fbf5a96-66c5-4026-a901-aff2e7ef5d0d
severity: MEDIUM
baseScore: 6.0
vectorString: AV:L/AC:H/AU:S/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: HIGH
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 1.5
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: 0fbf5a96-66c5-4026-a901-aff2e7ef5d0d // CNVD: CNVD-2019-07710

TYPE

Permission permission and access control

Trust: 0.2

sources: IVD: 0fbf5a96-66c5-4026-a901-aff2e7ef5d0d

PATCH

title:File upload vulnerability exists in WebNavigator component in Winccurl:https://www.cnvd.org.cn/patchinfo/show/156611

Trust: 0.6

sources: CNVD: CNVD-2019-07710

EXTERNAL IDS

db:CNVDid:CNVD-2019-07710

Trust: 0.8

db:IVDid:0FBF5A96-66C5-4026-A901-AFF2E7EF5D0D

Trust: 0.2

sources: IVD: 0fbf5a96-66c5-4026-a901-aff2e7ef5d0d // CNVD: CNVD-2019-07710

REFERENCES

url:http://www.siemens.com

Trust: 0.6

sources: CNVD: CNVD-2019-07710

SOURCES

db:IVDid:0fbf5a96-66c5-4026-a901-aff2e7ef5d0d
db:CNVDid:CNVD-2019-07710

LAST UPDATE DATE

2022-05-17T02:04:29.005000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2019-07710date:2019-03-25T00:00:00

SOURCES RELEASE DATE

db:IVDid:0fbf5a96-66c5-4026-a901-aff2e7ef5d0ddate:2019-03-21T00:00:00
db:CNVDid:CNVD-2019-07710date:2019-05-03T00:00:00