← Vulnerability feed

Vulnerability record · CVE-2011-4875 · published 3 February 2012

CVE-2011-4875: Siemens wincc flexible memory buffer overflow vulnerability

Siemens · Wincc Flexible

Stack-based buffer overflow in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime, when Transfer Mode is enabled, allows remote attackers to execute arbitrary code via vectors related to Unicode strings.

9.3 CVSS 2.0 High EPSS 14% · top 3.6% CWE-119 · Memory buffer overflow
9.3CVSS 2.0 base score
14%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime, when Transfer Mode is enabled, allows remote attackers to execute arbitrary code via vectors related to Unicode strings.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-4875 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2011-4509Siemens wincc flexible permissions and access controls vulnerabilityThe HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panel…EPSS 2.0%10.0CVE-2011-4513Siemens wincc flexible vulnerabilitySiemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; …EPSS 4.8%10.0CVE-2011-4514Siemens wincc flexible improper authentication vulnerabilityThe TELNET daemon in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels…EPSS 3.4%9.3CVE-2011-4508Siemens wincc flexible improper authentication vulnerabilityThe HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, C…EPSS 3.0%9.3CVE-2011-4876Siemens wincc flexible path traversal vulnerabilityDirectory traversal vulnerability in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); …EPSS 9.0%8.5CVE-2011-4879Siemens wincc flexible improper input validation vulnerabilityminiweb.exe in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; th…EPSS 12%8.2CVE-2017-12069Siemens simatic pcs7 xml external entity (xxe) vulnerabilityAn XXE vulnerability has been identified in OPC Foundation UA .NET Sample Code before 2017-03-21 and Local Discovery Server (LDS) before 1.03.367. Am…EPSS 2.9%7.8CVE-2023-30897Siemens wincc incorrect permission assignment vulnerabilityA vulnerability has been identified in SIMATIC WinCC (All versions < V7.5.2.13). Affected applications fail to set proper access rights for their ins…EPSS 0.21%

Source: NIST National Vulnerability Database (record CVE-2011-4875), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.