PT-2025-2757 · Siemens · Simatic S7-1200 Cpu+1
David Henrique Estevam De Andrade
·
Published
2025-01-14
·
Updated
2025-01-15
·
CVE-2024-47100
CVSS v4.0
7.2
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions:
SIMATIC S7-1200 CPU versions 1211C through 1217C
SIPLUS S7-1200 CPU versions 1212 through 1215
Description:
The web interface of the affected devices is vulnerable to Cross-Site Request Forgery (CSRF) attacks. This could allow an unauthenticated attacker to change the CPU mode by tricking a legitimate and authenticated user with sufficient permissions on the target CPU to click on a malicious link.
Recommendations:
For SIMATIC S7-1200 CPU versions 1211C through 1217C, restrict access to the web interface to minimize the risk of exploitation.
For SIPLUS S7-1200 CPU versions 1212 through 1215, consider disabling the web interface until a patch is available.
As a temporary workaround, avoid using the web interface for critical operations until the issue is resolved.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simatic S7-1200 Cpu
Siplus S7-1200 Cpu