DB: Siemens SIMATIC WinCC Default Password

This signature detects usage of a default account and password supplied with the Siemens SIMATIC WinCC SCADA device management application. Usage of this default account can allow an attacker access to the application's database.

Extended Description

Siemens SIMATIC WinCC is affected by a vulnerability that allows attackers to bypass security. An attacker can exploit this issue to bypass certain security restrictions and gain access to the application's database. Successfully exploiting this issue may lead to further attacks.

Affected Products

Siemens simatic_wincc

Short Name
DB:MS-SQL:WINCC-DEFAULT-PASS
Severity
Critical
Recommended
False
Recommended Action
Drop
Category
DB
Keywords
CVE-2010-2772 Default Password SIMATIC Siemens WinCC bid:41753
Release Date
07/21/2010
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
False Positive
Unknown
Vendors

Siemens

CVSS Score

6.9

Found a potential security threat?