Directory traversal vulnerability in miniweb.exe in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime allows remote attackers to read arbitrary files via a ..%5c (dot dot backslash) in a URI.
Conclusion & alert: CVE-2011-4878 is rated High Exploit Risk (78.3/100): CVSS High severity, with high exploitation likelihood (EPSS 14.11%, 94th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| 18166 | exploit_db | edb | 2011-11-28 | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-23 | 15.08% | 14.11% | -0.97% |
| 2 | 2026-03-10 | 19.08% | 15.08% | -4.00% |
| 3 | 2025-12-25 | — | 19.08% | — |
Full EPSS history (11 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.8 | 2.0 | HIGH |
|
10.0 | 6.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| siemens | wincc_flexible | 2004 | cpe:2.3:a:siemens:wincc_flexible:2004:*:*:*:*:*:*:* |
| siemens | wincc_flexible | 2005 | cpe:2.3:a:siemens:wincc_flexible:2005:*:*:*:*:*:*:* |
| siemens | wincc_flexible | 2007 | cpe:2.3:a:siemens:wincc_flexible:2007:*:*:*:*:*:*:* |
| siemens | wincc_flexible | 2008 | cpe:2.3:a:siemens:wincc_flexible:2008:*:*:*:*:*:*:* |
| siemens | wincc_flexible | 2008 | cpe:2.3:a:siemens:wincc_flexible:2008:sp1:*:*:*:*:*:* |
| siemens | wincc_flexible | 2008 | cpe:2.3:a:siemens:wincc_flexible:2008:sp2:*:*:*:*:*:* |
| siemens | wincc | <= v11 | cpe:2.3:a:siemens:wincc:*:sp2:*:*:*:*:*:* |
| siemens | wincc | v11 | cpe:2.3:a:siemens:wincc:v11:*:*:*:*:*:*:* |
| siemens | wincc | v11 | cpe:2.3:a:siemens:wincc:v11:sp1:*:*:*:*:*:* |
| siemens | simatic_hmi_panels | comfort_panels | cpe:2.3:a:siemens:simatic_hmi_panels:comfort_panels:*:*:*:*:*:*:* |
| siemens | simatic_hmi_panels | mobile_panels | cpe:2.3:a:siemens:simatic_hmi_panels:mobile_panels:*:*:*:*:*:*:* |
| siemens | simatic_hmi_panels | mp | cpe:2.3:a:siemens:simatic_hmi_panels:mp:*:*:*:*:*:*:* |
| siemens | simatic_hmi_panels | op | cpe:2.3:a:siemens:simatic_hmi_panels:op:*:*:*:*:*:*:* |
| siemens | simatic_hmi_panels | tp | cpe:2.3:a:siemens:simatic_hmi_panels:tp:*:*:*:*:*:*:* |
| siemens | wincc_runtime_advanced | v11 | cpe:2.3:a:siemens:wincc_runtime_advanced:v11:*:*:*:*:*:*:* |
| siemens | wincc_flexible_runtime | — | cpe:2.3:a:siemens:wincc_flexible_runtime:*:*:*:*:*:*:*:* |