Siemens SIMATIC WinCC Flexible 2004 / 2005 / 2007 / 2008 HMI Runtime — Default Password
Default username and password for the Siemens SIMATIC WinCC Flexible 2004 / 2005 / 2007 / 2008 HMI Runtime: Administrator / 100. Learn how to log in and how to change the default credentials.
Siemens SIMATIC WinCC Flexible Runtime (versions 2004 through 2008) ships with Administrator/100 as the default admin account. This credential protects the HMI runtime project, Sm@rtServer remote access session, and the integrated web server. Multiple Siemens security advisories (ICS-CERT ICSA-11-223-01) and the WinCC Flexible 2008 Security Hardening Guide document this default. Also carried into some WinCC Runtime Professional V12 deployments. CVE-2011-4508 assigned for this weak default.
| Username | Password | Access | Notes |
|---|---|---|---|
Administrator | 100 | Web UI | WinCC Flexible MiniWeb / Sm@rtServer remote access |
Administrator | 100 | Console | Runtime project administrator |
Responsible use
This database lists publicly documented default credentials so administrators can find and change them. Only use these on systems you own or are authorized to test.