Siemens SIMATIC WinCC Flexible is prone to multiple security vulnerabilities.
Credit:
The information has been provided by Gleb Gritsai, Alexander Zaitsev, Sergey Scherbel, Yuri Goltsev, Dmitry Serebryannikov, Sergey Bobrov, Denis Baranov, Andrey Medov and Siemens.
The original article can be found at: http://www.securityfocus.com/bid/53837
Attackers can exploit these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, execute arbitrary code in the context of the affected application, read arbitrary files on the system, redirect users to a potentially malicious site, access or modify data of an XML document, or cause denial-of-service conditions; other attacks may also be possible.
Vendor Status:
Siemens had issued an update for this vulnerability