PROTOCOL-SCADA -- Snort alerted on SCADA protocol activity. SCADA is used in Industrial Control Systems (ICS), programmable logic controllers for large scale systems, such as water treatment facilities. SCADA systems often require no authentication and use generic commands that are hard to screen for. Snort rules look for specific hardware and the traffic protocols they use, as these are often tied to a specific port or URI request.
PROTOCOL-SCADA Siemens SIMATIC WinCC flexible runtime directory traversal attempt
Directory traversal vulnerability in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime, when Transfer Mode is enabled, allows remote attackers to execute, read, create, modify, or delete arbitrary files via a .. (dot dot) in a string.
CVSS base score 9.3
CVSS impact score 10.0
CVSS exploitability score 8.6
Ease of Attack:
What To Look For
No public information
No known false positives
Talos research team.
This document was generated from data supplied by the national vulnerability database, a product of the national institute of standards and technology.
For more information see [nvd].