Siemens Simatic WinCC and PCS 7 SCADA system uses a hard-coded password, which allows local users to access a back-end database and gain privileges, as demonstrated in the wild in July 2010 by the Stuxnet worm, a different vulnerability than CVE-2010-2568.
2010-07-22T05:43:58.250
2025-04-11T00:51:21.963
Deferred
CVSSv3.1: 7.8 (HIGH)
AV:L/AC:M/Au:N/C:C/I:C/A:C
3.4
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | siemens | simatic_wincc | 6.2 | Yes |
Application | siemens | simatic_wincc | 7.0 | Yes |
Application | siemens | simatic_pcs_7 | 6.0 | Yes |
Application | siemens | simatic_pcs_7 | 6.1 | Yes |
Application | siemens | simatic_pcs_7 | 7.0 | Yes |
Application | siemens | simatic_pcs_7 | 7.0 | Yes |
Application | siemens | simatic_pcs_7 | 7.1 | Yes |
Application | siemens | simatic_pcs_7 | 7.1 | Yes |