Reversible Password Storage Vulnerability in Siemens WinCC (TIA Portal) 11

Reversible Password Storage Vulnerability in Siemens WinCC (TIA Portal) 11

CVE-2011-4515 · MEDIUM Severity

AV:L/AC:L/AU:N/C:P/I:P/A:P

Siemens WinCC (TIA Portal) 11 uses a reversible algorithm for storing HMI web-application passwords in world-readable and world-writable files, which allows local users to obtain sensitive information by leveraging (1) physical access or (2) Sm@rt Server access.

Learn more about our Web App Pen Testing.