A vulnerability has been identified in Siemens 7KT PAC1200 data manager (7KT1260) in all versions < V2.03. The integrated web server (port 80/tcp) of the affected devices could allow an unauthenticated remote attacker to perform administrative operations over the network.
The product requires authentication, but the product has an alternate path or channel that does not require authentication.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-971654.pdf | vendor advisory |
http://www.securityfocus.com/bid/101184 | vdb entry third party advisory |