APP: Siemens Simatic WinCC HmiLoad.exe Overflow

This signature detects attempts to exploit a known vulnerability in the Siemens Simatic WinCC HmiLoad.exe. A successful attack can result in arbitrary code execution or a denial-of-service condition.

Extended Description

Siemens SIMATIC WinCC Flexible is prone to multiple security vulnerabilities that affect the 'HmiLoad.exe' program. Attackers can exploit these issues to execute arbitrary code in the context of the affected application, read/write or delete arbitrary files outside of the server root directory, or cause denial-of-service conditions; other attacks may also be possible.

Affected Products

Siemens simatic_wincc_flexible

References

BugTraq: 50828

CVE: CVE-2011-4875

Short Name
SCADA:SIEMENS-SIMATIC-HMILOAD
Severity
Major
Recommended
False
Recommended Action
Drop
Category
SCADA
Keywords
CVE-2011-4875 CVE-2011-4877 HmiLoad.exe Overflow Siemens Simatic WinCC bid:50828
Release Date
11/05/2012
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
Port
tcp/2308,2920
False Positive
Unknown
Vendors

Siemens

CVSS Score

9.3

7.1

Found a potential security threat?