2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2013-0675" ,
"sourceIdentifier" : "ics-cert@hq.dhs.gov" ,
"published" : "2013-03-21T15:55:01.553" ,
2025-04-11 02:06:08 +00:00
"lastModified" : "2025-04-11T00:51:21.963" ,
"vulnStatus" : "Deferred" ,
2024-12-08 03:06:42 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "Buffer overflow in CCEServer (aka the central communications component) in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, allows remote attackers to cause a denial of service via a crafted packet."
} ,
{
"lang" : "es" ,
"value" : "Desbordamiento de b\u00fafer en CCEServer (tambi\u00e9n conocido como el componente central de comunicaciones) en Siemens WinCC antes de v7,2, tal como se utiliza en SIMATIC PCS v7 antes de v8,0 SP1 y otros productos, permite a atacantes remotos provocar una denegaci\u00f3n de servicio a trav\u00e9s de un paquete dise\u00f1ado."
}
] ,
"metrics" : {
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:A/AC:L/Au:N/C:N/I:N/A:C" ,
2024-11-22 19:15:24 +00:00
"baseScore" : 6.1 ,
2023-04-24 12:24:31 +02:00
"accessVector" : "ADJACENT_NETWORK" ,
"accessComplexity" : "LOW" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
2024-11-22 19:15:24 +00:00
"availabilityImpact" : "COMPLETE"
2023-04-24 12:24:31 +02:00
} ,
"baseSeverity" : "MEDIUM" ,
"exploitabilityScore" : 6.5 ,
"impactScore" : 6.9 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : false
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-119"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:siemens:simatic_pcs7:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "8.0" ,
"matchCriteriaId" : "6EFF12A0-B105-4225-B818-F858C75047B0"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:siemens:simatic_pcs7:7.1:sp3:*:*:*:*:*:*" ,
"matchCriteriaId" : "33FA164B-E269-4140-AC85-2623356AF636"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:siemens:wincc:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "7.1" ,
"matchCriteriaId" : "B34F3397-62D2-4D9C-A3DA-1BEE4A2A69FC"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:siemens:wincc:5.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "B4CB277F-7ECB-4F44-8BB5-A3D350486EE7"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:siemens:wincc:5.0:sp1:*:*:*:*:*:*" ,
"matchCriteriaId" : "616535F1-F609-408B-AE48-61ACF48748A1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:siemens:wincc:6.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7F322FCB-32F4-4C5A-A7F5-F7EF41188C88"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:siemens:wincc:6.0:sp2:*:*:*:*:*:*" ,
"matchCriteriaId" : "69822DB4-DC79-4F88-A470-5AC512C77377"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:siemens:wincc:6.0:sp3:*:*:*:*:*:*" ,
"matchCriteriaId" : "996DE8BD-DD51-41EF-9882-C2BD2CC5FE53"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:siemens:wincc:6.0:sp4:*:*:*:*:*:*" ,
"matchCriteriaId" : "945C8B46-4CDA-4143-889C-30E30E93DB29"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:siemens:wincc:7.0:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A33F9015-7058-419A-8762-CB2AE4ACF1A7"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:siemens:wincc:7.0:sp1:*:*:*:*:*:*" ,
"matchCriteriaId" : "E6271FCC-CCF6-4D31-801A-B4B0DC4639DD"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:siemens:wincc:7.0:sp2:*:*:*:*:*:*" ,
"matchCriteriaId" : "DF7A6B2B-D573-4285-B3B4-136F2BE7E710"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:siemens:wincc:7.0:sp3:*:*:*:*:*:*" ,
"matchCriteriaId" : "111D0F4D-2B67-46E8-BF8D-5D30EFE561EE"
}
]
}
]
}
] ,
"references" : [
{
"url" : "http://ics-cert.us-cert.gov/pdf/ICSA-13-079-02.pdf" ,
"source" : "ics-cert@hq.dhs.gov" ,
"tags" : [
"US Government Resource"
]
} ,
{
"url" : "http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-714398.pdf" ,
"source" : "ics-cert@hq.dhs.gov" ,
"tags" : [
"Vendor Advisory"
]
2024-11-22 19:15:24 +00:00
} ,
{
"url" : "http://ics-cert.us-cert.gov/pdf/ICSA-13-079-02.pdf" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"US Government Resource"
]
} ,
{
"url" : "http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-714398.pdf" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Vendor Advisory"
]
2023-04-24 12:24:31 +02:00
}
]
}