CVE-2010-2772

Siemens Simatic WinCC and PCS 7 SCADA system uses a hard-coded password, which allows local users to access a back-end database and gain privileges, as demonstrated in the wild in July 2010 by the Stuxnet worm, a different vulnerability than CVE-2010-2568.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 24%
VendorProductVersion
siemenssimatic_wincc
6.2
siemenssimatic_wincc
7.0
siemenssimatic_pcs_7
6.0
siemenssimatic_pcs_7
6.1
siemenssimatic_pcs_7
7.0
siemenssimatic_pcs_7
7.0:sp1
siemenssimatic_pcs_7
7.1
siemenssimatic_pcs_7
7.1:sp1
𝑥
= Vulnerable software versions
References