PT-2014-1955 · Siemens · Simatic S7-1500 Cpu+1
Aleksandr Timorin
+4
·
Published
2014-03-16
·
Updated
2014-03-26
·
CVE-2014-2249
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Siemens SIMATIC S7-1500 CPU PLC devices versions prior to 1.5.0
Siemens SIMATIC S7-1200 CPU PLC devices versions prior to 4.0
Description
A cross-site request forgery (CSRF) issue affects the software, allowing remote attackers to hijack the authentication of victims via unknown vectors. The vulnerability is also described as affecting the embedded server of the Simatic S7-1200 programmable logic controller, specifically on port 80 TCP and port 443 TCP, enabling cross-site request forgery.
Recommendations
For Siemens SIMATIC S7-1500 CPU PLC devices versions prior to 1.5.0, update the firmware to version 1.5.0 or later.
For Siemens SIMATIC S7-1200 CPU PLC devices versions prior to 4.0, update the firmware to version 4.0 or later.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simatic S7-1200 Cpu
Simatic S7-1500 Cpu