|
|
| |
| MiniWeb is prone to a denial-of-service vulnerability and a directory-traversal vulnerability. |
| |
Credit:
The information has been provided by Luigi Auriemma.
The original article can be found at: http://www.securityfocus.com/bid/50827
|
| |
Vulnerable Systems:
* Stanley Huang MiniWeb
* Siemens SIMATIC WinCC flexible Runtime
* Siemens SIMATIC WinCC Flexible 2008 SP2
Exploiting these issues may allow remote attackers to crash the server or download arbitrary files within the context of the affected server.
Vendor Status:
Vendor had issued an update for this vulnerability
Patch Availability:
http://www.automation.siemens.com/mcms/human-machine-interface/en/visualization-software/wincc-flexible/wincc-flexible-runtime/Pages/Default.aspx
Disclosure Timeline:
Initial Release: Nov 28 2011
|
|
blog comments powered by
|