Show plain JSON{"id": "CVE-2013-0674", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 6.8, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "MEDIUM", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 6.4, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}]}, "published": "2013-03-21T15:55:01.533", "references": [{"url": "http://ics-cert.us-cert.gov/pdf/ICSA-13-079-02.pdf", "tags": ["US Government Resource"], "source": "ics-cert@hq.dhs.gov"}, {"url": "http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-714398.pdf", "tags": ["Vendor Advisory"], "source": "ics-cert@hq.dhs.gov"}, {"url": "http://ics-cert.us-cert.gov/pdf/ICSA-13-079-02.pdf", "tags": ["US Government Resource"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-714398.pdf", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Deferred", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-119"}]}], "descriptions": [{"lang": "en", "value": "Buffer overflow in the RegReader ActiveX control in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, allows remote attackers to execute arbitrary code via a long parameter."}, {"lang": "es", "value": "Desbordamiento de b\u00fafer en el control ActiveX RegReader en Siemens WinCC antes de v7,2, tal como se utiliza en SIMATIC PCS v7 antes de v8,0 SP1 y otros productos, permite a atacantes remotos ejecutar c\u00f3digo arbitrario a trav\u00e9s de un par\u00e1metro largo."}], "lastModified": "2025-04-11T00:51:21.963", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:siemens:simatic_pcs7:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6EFF12A0-B105-4225-B818-F858C75047B0", "versionEndIncluding": "8.0"}, {"criteria": "cpe:2.3:a:siemens:simatic_pcs7:7.1:sp3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "33FA164B-E269-4140-AC85-2623356AF636"}, {"criteria": "cpe:2.3:a:siemens:wincc:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B34F3397-62D2-4D9C-A3DA-1BEE4A2A69FC", "versionEndIncluding": "7.1"}, {"criteria": "cpe:2.3:a:siemens:wincc:5.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B4CB277F-7ECB-4F44-8BB5-A3D350486EE7"}, {"criteria": "cpe:2.3:a:siemens:wincc:5.0:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "616535F1-F609-408B-AE48-61ACF48748A1"}, {"criteria": "cpe:2.3:a:siemens:wincc:6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7F322FCB-32F4-4C5A-A7F5-F7EF41188C88"}, {"criteria": "cpe:2.3:a:siemens:wincc:6.0:sp2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "69822DB4-DC79-4F88-A470-5AC512C77377"}, {"criteria": "cpe:2.3:a:siemens:wincc:6.0:sp3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "996DE8BD-DD51-41EF-9882-C2BD2CC5FE53"}, {"criteria": "cpe:2.3:a:siemens:wincc:6.0:sp4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "945C8B46-4CDA-4143-889C-30E30E93DB29"}, {"criteria": "cpe:2.3:a:siemens:wincc:7.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A33F9015-7058-419A-8762-CB2AE4ACF1A7"}, {"criteria": "cpe:2.3:a:siemens:wincc:7.0:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E6271FCC-CCF6-4D31-801A-B4B0DC4639DD"}, {"criteria": "cpe:2.3:a:siemens:wincc:7.0:sp2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DF7A6B2B-D573-4285-B3B4-136F2BE7E710"}, {"criteria": "cpe:2.3:a:siemens:wincc:7.0:sp3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "111D0F4D-2B67-46E8-BF8D-5D30EFE561EE"}], "operator": "OR"}]}], "sourceIdentifier": "ics-cert@hq.dhs.gov"}