PT-2014-1955 · Siemens · Simatic S7-1500 Cpu+1

Aleksandr Timorin

+4

·

Published

2014-03-16

·

Updated

2014-03-26

·

CVE-2014-2249

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Siemens SIMATIC S7-1500 CPU PLC devices versions prior to 1.5.0 Siemens SIMATIC S7-1200 CPU PLC devices versions prior to 4.0
Description A cross-site request forgery (CSRF) issue affects the software, allowing remote attackers to hijack the authentication of victims via unknown vectors. The vulnerability is also described as affecting the embedded server of the Simatic S7-1200 programmable logic controller, specifically on port 80 TCP and port 443 TCP, enabling cross-site request forgery.
Recommendations For Siemens SIMATIC S7-1500 CPU PLC devices versions prior to 1.5.0, update the firmware to version 1.5.0 or later. For Siemens SIMATIC S7-1200 CPU PLC devices versions prior to 4.0, update the firmware to version 4.0 or later.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-10402
CVE-2014-2249

Affected Products

Simatic S7-1200 Cpu
Simatic S7-1500 Cpu