Vulnerability Description
Siemens Simatic WinCC and PCS 7 SCADA system uses a hard-coded password, which allows local users to access a back-end database and gain privileges, as demonstrated in the wild in July 2010 by the Stuxnet worm, a different vulnerability than CVE-2010-2568.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Simatic Wincc | 6.2 |
| Siemens | Simatic Pcs 7 | 6.0 |
Related Weaknesses (CWE)
References
- http://ics-cert.us-cert.gov/advisories/ICSA-12-205-01Third Party AdvisoryUS Government Resource
- http://infoworld.com/d/security-central/new-weaponized-virus-targets-industrial-Press/Media Coverage
- http://infoworld.com/d/security-central/siemens-warns-users-dont-change-passwordPress/Media Coverage
- http://krebsonsecurity.com/2010/07/experts-warn-of-new-windows-shortcut-flaw/Press/Media Coverage
- http://secunia.com/advisories/40682Broken Link
- http://support.automation.siemens.com/WW/llisapi.dll?func=cslib.csinfo&lang=en&oNot Applicable
- http://www.automation.siemens.com/forum/guests/PostShow.aspx?PostID=16127&16127&Broken Link
- http://www.f-secure.com/weblog/archives/00001987.htmlThird Party Advisory
- http://www.sea.siemens.com/us/News/Industrial/Pages/WinCC_Update.aspxBroken LinkVendor Advisory
- http://www.securityfocus.com/bid/41753Broken LinkThird Party AdvisoryVDB Entry
- http://www.vupen.com/english/advisories/2010/1893Broken Link
- http://www.wilderssecurity.com/showpost.php?p=1712134&postcount=22ExploitIssue Tracking
- http://www.wired.com/threatlevel/2010/07/siemens-scada/Press/Media CoverageThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/60587Third Party AdvisoryVDB Entry
- http://ics-cert.us-cert.gov/advisories/ICSA-12-205-01Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2010-2772?
CVE-2010-2772 is a vulnerability with a CVSS score of 7.8 (HIGH). Siemens Simatic WinCC and PCS 7 SCADA system uses a hard-coded password, which allows local users to access a back-end database and gain privileges, as demonstrated in the wild in July 2010 by the Stu...
How severe is CVE-2010-2772?
CVE-2010-2772 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-2772?
Check the references section above for vendor advisories and patch information. Affected products include: Siemens Simatic Wincc, Siemens Simatic Pcs 7.