Siemens WinCC (TIA Portal) Web Server URL Handling Remote Source Code Disclosure Vulnerability
6 May. 2013
Summary
Siemens WinCC (TIA Portal) Web Server URL Handling suffers from remote source code disclosure vulnerability.
Credit:
The information has been provided by Gleb Gritsai , Sergey Bobrov , Artem Chaykin , Roman Ilin , Timur Yunusov , Ilya Karpov , .
The original article can be found at: http://ics-cert.us-cert.gov/pdf/ICSA-13-079-03.pdf
Siemens WinCC (TIA Portal) contains a flaw in the Web Server that may lead to unauthorized disclosure of sensitive information. The issue is triggered during the handling of a specially crafted URL. This may allow a remote attacker to gain access to source code information.