Unrated severityNVD Advisory· Published Jun 14, 2013· Updated Apr 29, 2026
CVE-2013-3958
CVE-2013-3958
Description
The login implementation in the Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, has a hardcoded account, which makes it easier for remote attackers to obtain access via an unspecified request.
Affected products
9cpe:2.3:a:siemens:simatic_pcs7:8.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:siemens:simatic_pcs7:8.0:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:simatic_pcs7:*:sp1:*:*:*:*:*:*range: <=8.0
cpe:2.3:a:siemens:wincc:*:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:siemens:wincc:*:*:*:*:*:*:*:*range: <=7.2
- cpe:2.3:a:siemens:wincc:7.0:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:wincc:7.0:sp1:*:*:*:*:*:*
- cpe:2.3:a:siemens:wincc:7.0:sp2:*:*:*:*:*:*
- cpe:2.3:a:siemens:wincc:7.0:sp3:*:*:*:*:*:*
- cpe:2.3:a:siemens:wincc:7.1:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:wincc:7.1:sp1:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.