Vulnerability Details CVE-2013-3958
The login implementation in the Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, has a hardcoded account, which makes it easier for remote attackers to obtain access via an unspecified request.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 61.2%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2013-3958
-
cpe:2.3:a:siemens:simatic_pcs7:8.0
-
cpe:2.3:a:siemens:wincc:5.0
-
cpe:2.3:a:siemens:wincc:6.0
-
cpe:2.3:a:siemens:wincc:7.0
-
cpe:2.3:a:siemens:wincc:7.1
-
cpe:2.3:a:siemens:wincc:7.2