PT-2014-1955 · Siemens · Simatic S7-1500 Cpu+1
Aleksandr Timorin
+4
·
Publicado
2014-03-16
·
Atualizado
2014-03-26
·
CVE-2014-2249
CVSS v2.0
5.8
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Siemens SIMATIC S7-1500 CPU PLC devices versions prior to 1.5.0
Siemens SIMATIC S7-1200 CPU PLC devices versions prior to 4.0
Description
A cross-site request forgery (CSRF) issue affects the software, allowing remote attackers to hijack the authentication of victims via unknown vectors. The vulnerability is also described as affecting the embedded server of the Simatic S7-1200 programmable logic controller, specifically on port 80 TCP and port 443 TCP, enabling cross-site request forgery.
Recommendations
For Siemens SIMATIC S7-1500 CPU PLC devices versions prior to 1.5.0, update the firmware to version 1.5.0 or later.
For Siemens SIMATIC S7-1200 CPU PLC devices versions prior to 4.0, update the firmware to version 4.0 or later.
Correção
CSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Simatic S7-1200 Cpu
Simatic S7-1500 Cpu