High severity7.8NVD Advisory· Published Jul 22, 2010· Updated Apr 29, 2026
CVE-2010-2772
CVE-2010-2772
Description
Siemens Simatic WinCC and PCS 7 SCADA system uses a hard-coded password, which allows local users to access a back-end database and gain privileges, as demonstrated in the wild in July 2010 by the Stuxnet worm, a different vulnerability than CVE-2010-2568.
Affected products
8cpe:2.3:a:siemens:simatic_wincc:6.2:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:siemens:simatic_wincc:6.2:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:simatic_wincc:7.0:*:*:*:*:*:*:*
cpe:2.3:a:siemens:simatic_pcs_7:6.0:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:siemens:simatic_pcs_7:6.0:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:simatic_pcs_7:6.1:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:simatic_pcs_7:7.0:-:*:*:*:*:*:*
- cpe:2.3:a:siemens:simatic_pcs_7:7.0:sp1:*:*:*:*:*:*
- cpe:2.3:a:siemens:simatic_pcs_7:7.1:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:simatic_pcs_7:7.1:sp1:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
14- www.wilderssecurity.com/showpost.phpnvdExploitIssue Tracking
- ics-cert.us-cert.gov/advisories/ICSA-12-205-01nvdThird Party AdvisoryUS Government Resource
- www.f-secure.com/weblog/archives/00001987.htmlnvdThird Party Advisory
- www.sea.siemens.com/us/News/Industrial/Pages/WinCC_Update.aspxnvdBroken LinkVendor Advisory
- www.securityfocus.com/bid/41753nvdBroken LinkThird Party AdvisoryVDB Entry
- www.wired.com/threatlevel/2010/07/siemens-scada/nvdPress/Media CoverageThird Party Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/60587nvdThird Party AdvisoryVDB Entry
- infoworld.com/d/security-central/new-weaponized-virus-targets-industrial-secrets-725nvdPress/Media Coverage
- infoworld.com/d/security-central/siemens-warns-users-dont-change-passwords-after-worm-attack-915nvdPress/Media Coverage
- krebsonsecurity.com/2010/07/experts-warn-of-new-windows-shortcut-flaw/nvdPress/Media Coverage
- secunia.com/advisories/40682nvdBroken Link
- support.automation.siemens.com/WW/llisapi.dllnvdNot Applicable
- www.automation.siemens.com/forum/guests/PostShow.aspxnvdBroken Link
- www.vupen.com/english/advisories/2010/1893nvdBroken Link
News mentions
0No linked articles in our index yet.