CVE-2012-4693
Severity CVSS v4.0:
Pending analysis
Type:
CWE-310
Cryptographic Issues
Publication date:
18/12/2012
Last modified:
11/04/2025
Description
Invensys Wonderware InTouch 2012 R2 and earlier and Siemens ProcessSuite use a weak encryption algorithm for data in Ps_security.ini, which makes it easier for local users to discover passwords by reading this file.
Impact
Base Score 2.0
1.90
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:invensys:wonderware_intouch:*:r2:*:*:*:*:*:* | 2012 (including) | |
cpe:2.3:a:siemens:processsuite:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-370812.pdf
- http://www.us-cert.gov/control_systems/pdf/ICSA-12-348-01.pdf
- http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-370812.pdf
- http://www.us-cert.gov/control_systems/pdf/ICSA-12-348-01.pdf