Описание
A vulnerability in SIEMENS SIMATIC WinCC (All versions < SIMATIC WinCC V7.2) and SIEMENS SIMATIC PCS 7 (All versions < SIMATIC PCS 7 V8.0 SP1) could allow a remote attacker to crash an ActiveX component or leak parts of the application memory if a user is tricked into clicking on a malicious link under certain conditions.
Ссылки
Уязвимые конфигурации
Конфигурация 1Версия до 8.0 (включая)Версия до 7.1 (включая)
Одно из
cpe:2.3:a:siemens:simatic_pcs_7:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:simatic_wincc:*:*:*:*:*:*:*:*
EPSS
Процентиль: 65%
0.00489
Низкий
8.1 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-111
CWE-254
Связанные уязвимости
CVSS3: 8.1
github
больше 3 лет назад
A vulnerability in SIEMENS SIMATIC WinCC (All versions < SIMATIC WinCC V7.2) and SIEMENS SIMATIC PCS 7 (All versions < SIMATIC PCS 7 V8.0 SP1) could allow a remote attacker to crash an ActiveX component or leak parts of the application memory if a user is tricked into clicking on a malicious link under certain conditions.
EPSS
Процентиль: 65%
0.00489
Низкий
8.1 High
CVSS3
5.8 Medium
CVSS2
Дефекты
CWE-111
CWE-254