Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Project administration application in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, has a hardcoded encryption key, which allows remote attackers to obtain sensitive information by extracting this key from another product installation and then employing this key during the sniffing of network traffic on TCP port 1030.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Siemens SIMATIC WinCC 安全漏洞
Vulnerability Description
Siemens SIMATIC WinCC是德国西门子(Siemens)公司的一套自动化的数据采集与监控(SCADA)系统。该系统提供过程监视、数据采集等功能。 PCS7和其他产品上的Siemens SIMATIC WinCC 7.3之前版本的Project administration应用程序中存在安全漏洞,该漏洞源于程序使用硬编码的加密密钥。远程攻击者可通过在嗅探TCP 1030端口流量期间,从其他产品中提取密钥后利用此密钥,获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A