« Volver al listado

CVE-2011-4877

Estado: ModificadaAlta (7.1)—

HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime, when Transfer Mode is enabled, allows remote attackers to cause a denial of service (application crash) by sending crafted data over TCP.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (5)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2011-4877",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.1,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:C",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 6.9,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cret@cert.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-02-03T20:55:01.983",
  "references": [
    {
      "url": "http://aluigi.org/adv/winccflex_1-adv.txt",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.exploit-db.com/exploits/18166",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.osvdb.org/77382",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-345442.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-11-332-02.pdf",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-11-332-02A.pdf",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.us-cert.gov/control_systems/pdf/ICSA-12-030-01.pdf",
      "tags": [
        "US Government Resource"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/71451",
      "source": "cret@cert.org"
    },
    {
      "url": "http://aluigi.org/adv/winccflex_1-adv.txt",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.exploit-db.com/exploits/18166",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/77382",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-345442.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-11-332-02.pdf",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-11-332-02A.pdf",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.us-cert.gov/control_systems/pdf/ICSA-12-030-01.pdf",
      "tags": [
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/71451",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime, when Transfer Mode is enabled, allows remote attackers to cause a denial of service (application crash) by sending crafted data over TCP."
    },
    {
      "lang": "es",
      "value": "HmiLoad del cargador en tiempo de ejecución (\"runtime loader\") de Siemens WinCC flexible 2004, 2005, 2007 y 2008; WinCC V11 (TIA portal); the TP, OP, MP, Comfort Panels y Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced y WinCC flexible Runtime, cuando el modo de transferencia (\"Transfer Mode\") está habilitado, permite a atacantes remotos provocar una denegación de servicio (caída de la aplicación) enviando datos modificados sobre TCP."
    }
  ],
  "lastModified": "2026-06-16T23:35:33.663",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:siemens:wincc_flexible:2004:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7D596C29-36F8-44F2-897D-FD107769E5A9"
            },
            {
              "criteria": "cpe:2.3:a:siemens:wincc_flexible:2005:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2D84E29A-4BC2-4229-83C3-D9F7A641D19C"
            },
            {
              "criteria": "cpe:2.3:a:siemens:wincc_flexible:2007:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9B3ADDE1-1F91-43E7-A3C3-3069916F4B23"
            },
            {
              "criteria": "cpe:2.3:a:siemens:wincc_flexible:2008:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1432EC7A-47B2-41D1-B90B-72DBB79AC266"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:siemens:wincc:v11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "18A9883B-80E1-4B2E-88DA-D2326AE3DC08"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:siemens:simatic_hmi_panels:comfort_panels:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DC593746-B329-43EA-8CA1-AA56AC5A3B10"
            },
            {
              "criteria": "cpe:2.3:a:siemens:simatic_hmi_panels:mobile_panels:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1DF877E8-A0D1-4444-99F2-8A3E8ED4D31B"
            },
            {
              "criteria": "cpe:2.3:a:siemens:simatic_hmi_panels:mp:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "442AC914-BDD5-4D0C-9E04-88F60EE2B730"
            },
            {
              "criteria": "cpe:2.3:a:siemens:simatic_hmi_panels:op:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D9749966-1666-4F7D-90D0-17AFBB88AE83"
            },
            {
              "criteria": "cpe:2.3:a:siemens:simatic_hmi_panels:tp:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9471D239-08B1-4076-82F7-2B73F4E343CE"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:siemens:wincc_runtime_advanced:v11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1AE3AE80-C7A2-4581-993A-536936F6D315"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:siemens:wincc_flexible_runtime:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6F785262-BBFB-4A0C-A7DC-97F5D6B94BB0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cret@cert.org"
}