cpe:/a:siemens:simatic_pcs7:8.0 cpe:/a:siemens:wincc:5.0 cpe:/a:siemens:wincc:5.0:sp1 cpe:/a:siemens:wincc:6.0 cpe:/a:siemens:wincc:6.0:sp2 cpe:/a:siemens:wincc:6.0:sp3 cpe:/a:siemens:wincc:6.0:sp4 cpe:/a:siemens:wincc:7.0 cpe:/a:siemens:wincc:7.0:sp1 cpe:/a:siemens:wincc:7.0:sp2 cpe:/a:siemens:wincc:7.0:sp3 CVE-2012-3032 2012-09-18T10:55:01.537-04:00 2012-09-19T10:03:28.030-04:00 7.5 NETWORK LOW NONE PARTIAL PARTIAL PARTIAL http://nvd.nist.gov 2012-09-19T10:03:00.000-04:00 MISC http://en.securitylab.ru/lab/PT-2012-44 CONFIRM http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-864051.pdf MISC http://www.us-cert.gov/control_systems/pdf/ICSA-12-256-01.pdf SQL injection vulnerability in WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, allows remote attackers to execute arbitrary SQL commands via a crafted SOAP message.