PT-2025-2757 · Siemens · Simatic S7-1200 Cpu+1

David Henrique Estevam De Andrade

·

Published

2025-01-14

·

Updated

2025-01-15

·

CVE-2024-47100

CVSS v4.0

7.2

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: SIMATIC S7-1200 CPU versions 1211C through 1217C SIPLUS S7-1200 CPU versions 1212 through 1215
Description: The web interface of the affected devices is vulnerable to Cross-Site Request Forgery (CSRF) attacks. This could allow an unauthenticated attacker to change the CPU mode by tricking a legitimate and authenticated user with sufficient permissions on the target CPU to click on a malicious link.
Recommendations: For SIMATIC S7-1200 CPU versions 1211C through 1217C, restrict access to the web interface to minimize the risk of exploitation. For SIPLUS S7-1200 CPU versions 1212 through 1215, consider disabling the web interface until a patch is available. As a temporary workaround, avoid using the web interface for critical operations until the issue is resolved.

Fix

CSRF

Weakness Enumeration

Related Identifiers

BDU:2025-01562
CVE-2024-47100

Affected Products

Simatic S7-1200 Cpu
Siplus S7-1200 Cpu