← Vulnerability feed

Vulnerability record · CVE-2013-3957 · published 14 June 2013

CVE-2013-3957: Siemens simatic pcs7 sql injection vulnerability

Siemens · Simatic Pcs7

SQL injection vulnerability in the login screen in the Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

7.5 CVSS 2.0 High EPSS 1.8% · top 22.5% CWE-89 · SQL injection
7.5CVSS 2.0 base score
1.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
2References
16 Jun 2026Last modified by NVD

Description

SQL injection vulnerability in the login screen in the Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-3957 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2014-8551Siemens simatic pcs 7 code injection vulnerabilityThe WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2; SIMATIC PCS 7 7.1 through SP4, 8.0 through S…EPSS 5.3%10.0CVE-2011-4509Siemens wincc flexible permissions and access controls vulnerabilityThe HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panel…EPSS 2.0%10.0CVE-2011-4514Siemens wincc flexible improper authentication vulnerabilityThe TELNET daemon in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels…EPSS 3.4%10.0CVE-2011-4513Siemens wincc flexible vulnerabilitySiemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; …EPSS 4.8%9.3CVE-2011-4876Siemens wincc flexible path traversal vulnerabilityDirectory traversal vulnerability in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); …EPSS 9.0%9.3CVE-2011-4875Siemens wincc flexible memory buffer overflow vulnerabilityStack-based buffer overflow in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP…EPSS 14%9.3CVE-2011-4508Siemens wincc flexible improper authentication vulnerabilityThe HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, C…EPSS 3.0%8.5CVE-2011-4879Siemens wincc flexible improper input validation vulnerabilityminiweb.exe in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; th…EPSS 12%

Source: NIST National Vulnerability Database (record CVE-2013-3957), CISA KEV, FIRST EPSS (scores of 2026-10-01). This page is refreshed as NVD updates the record.