PT-2014-1955 · Siemens · Simatic S7-1500 Cpu+1

Aleksandr Timorin

+4

·

Publicado

2014-03-16

·

Atualizado

2014-03-26

·

CVE-2014-2249

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Siemens SIMATIC S7-1500 CPU PLC devices versions prior to 1.5.0 Siemens SIMATIC S7-1200 CPU PLC devices versions prior to 4.0
Description A cross-site request forgery (CSRF) issue affects the software, allowing remote attackers to hijack the authentication of victims via unknown vectors. The vulnerability is also described as affecting the embedded server of the Simatic S7-1200 programmable logic controller, specifically on port 80 TCP and port 443 TCP, enabling cross-site request forgery.
Recommendations For Siemens SIMATIC S7-1500 CPU PLC devices versions prior to 1.5.0, update the firmware to version 1.5.0 or later. For Siemens SIMATIC S7-1200 CPU PLC devices versions prior to 4.0, update the firmware to version 4.0 or later.

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-10402
CVE-2014-2249

Produtos afetados

Simatic S7-1200 Cpu
Simatic S7-1500 Cpu