« Volver al listado

CVE-2011-4512

Estado: ModificadaMedia (5)—

CRLF injection vulnerability in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (5)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2011-4512",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cret@cert.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-02-03T20:55:01.453",
  "references": [
    {
      "url": "http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-345442.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.us-cert.gov/control_systems/pdf/ICSA-12-030-01.pdf",
      "tags": [
        "US Government Resource"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-345442.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.us-cert.gov/control_systems/pdf/ICSA-12-030-01.pdf",
      "tags": [
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "CRLF injection vulnerability in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de inyección CRLF en el servidor web HMI de Siemens WinCC flexible 2004, 2005, 2007 y 2008 anteriores a SP3; WinCC V11 (TIA portal) anteriores a SP2 Update 1; TP, OP, MP, Comfort Panels y Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; y WinCC flexible Runtime permite a atacantes remotos inyectar cabeceras HTTP arbitrarios y realizar ataques de división de respuesta HTTP a través de vectores sin especificar."
    }
  ],
  "lastModified": "2026-06-16T23:34:58.020",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:siemens:wincc_flexible:2004:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7D596C29-36F8-44F2-897D-FD107769E5A9"
            },
            {
              "criteria": "cpe:2.3:a:siemens:wincc_flexible:2005:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2D84E29A-4BC2-4229-83C3-D9F7A641D19C"
            },
            {
              "criteria": "cpe:2.3:a:siemens:wincc_flexible:2007:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9B3ADDE1-1F91-43E7-A3C3-3069916F4B23"
            },
            {
              "criteria": "cpe:2.3:a:siemens:wincc_flexible:2008:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1432EC7A-47B2-41D1-B90B-72DBB79AC266"
            },
            {
              "criteria": "cpe:2.3:a:siemens:wincc_flexible:2008:sp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1A4B1323-9AF3-424F-925A-A62F35E575E0"
            },
            {
              "criteria": "cpe:2.3:a:siemens:wincc_flexible:2008:sp2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E454C72B-7804-402B-9C6A-687BF2C45D39"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:siemens:wincc:*:sp2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9FE44373-06BD-4AA0-8778-06F2A150510C",
              "versionEndIncluding": "v11"
            },
            {
              "criteria": "cpe:2.3:a:siemens:wincc:v11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "18A9883B-80E1-4B2E-88DA-D2326AE3DC08"
            },
            {
              "criteria": "cpe:2.3:a:siemens:wincc:v11:sp1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F53FDA20-FE97-4BA3-9165-F0BD7A25FA5F"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:siemens:simatic_hmi_panels:comfort_panels:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DC593746-B329-43EA-8CA1-AA56AC5A3B10"
            },
            {
              "criteria": "cpe:2.3:a:siemens:simatic_hmi_panels:mobile_panels:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1DF877E8-A0D1-4444-99F2-8A3E8ED4D31B"
            },
            {
              "criteria": "cpe:2.3:a:siemens:simatic_hmi_panels:mp:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "442AC914-BDD5-4D0C-9E04-88F60EE2B730"
            },
            {
              "criteria": "cpe:2.3:a:siemens:simatic_hmi_panels:op:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D9749966-1666-4F7D-90D0-17AFBB88AE83"
            },
            {
              "criteria": "cpe:2.3:a:siemens:simatic_hmi_panels:tp:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9471D239-08B1-4076-82F7-2B73F4E343CE"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:siemens:wincc_runtime_advanced:v11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1AE3AE80-C7A2-4581-993A-536936F6D315"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:siemens:wincc_flexible_runtime:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6F785262-BBFB-4A0C-A7DC-97F5D6B94BB0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cret@cert.org"
}