Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rfm5-4c4m-2vcc

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Project administration application in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, has a hardcoded encryption key, which allows remote attackers to obtain sensitive information by extracting this key from another product installation and then employing this key during the sniffing of network traffic on TCP port 1030.

The Project administration application in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, has a hardcoded encryption key, which allows remote attackers to obtain sensitive information by extracting this key from another product installation and then employing this key during the sniffing of network traffic on TCP port 1030.

EPSS

Процентиль: 46%
0.00231
Низкий

Связанные уязвимости

nvd
около 11 лет назад

The Project administration application in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, has a hardcoded encryption key, which allows remote attackers to obtain sensitive information by extracting this key from another product installation and then employing this key during the sniffing of network traffic on TCP port 1030.

fstec
больше 12 лет назад

Уязвимость автоматизированной системы управления технологическими процессами SIMATIC WinCC, позволяющая удаленному злоумышленнику повысить уровень своих привилегий

EPSS

Процентиль: 46%
0.00231
Низкий