Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
CRLF injection vulnerability in the HMI web application in Siemens WinCC (TIA Portal) 11 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Siemens WinCC HMI web CRLF注入漏洞
Vulnerability Description
Siemens SIMATIC WinCC是德国西门子(Siemens)公司的一套自动化的数据采集与监控(SCADA)系统。该系统提供过程监视、数据采集等功能。 Siemens WinCC (TIA Portal) 11版本中的HMI web应用程序中存在CRLF注入漏洞。通过特制的URL,远程攻击者利用该漏洞注入任意HTTP头以及进行HTTP响应拆分攻击。
CVSS Information
N/A
Vulnerability Type
N/A