VDB
ICSA-24-284-01
ICSA-24-284-01
PUBLISHED
CVSS 4.699999809265137 MEDIUM
Several SIMATIC S7-1500 and S7-1200 CPU versions are affected by an open redirect vulnerability that could allow an attacker to make the web server of affected devices redirect a legitimate user to an attacker-chosen URL. For a successful attack, the legitimate user must actively click on an attacker-crafted link. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens recommends specific countermeasures for products where fixes are not, or not yet available.
Risk Scores
CVSS v3.1
4.699999809265137
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SIMATIC ET 200SP CPU 1514SP F-2 PN (6ES7514-2SN03-0AB0) | ||
| SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) V3 CPUs - Windows OS | ||
| SIMATIC ET 200SP CPU 1514SP-2 PN (6ES7514-2DN03-0AB0) | ||
| SIMATIC ET 200SP CPU 1510SP F-1 PN (6ES7510-1SK03-0AB0) | ||
| SIMATIC Drive Controller CPU 1504D TF (6ES7615-4DF10-0AB0) | ||
| SIMATIC S7-1200 CPU 1211C AC/DC/Rly (6ES7211-1BE40-0XB0) | ||
| SIMATIC ET 200SP CPU 1510SP F-1 PN (6ES7510-1SJ01-0AB0) | ||
| SIMATIC S7-1200 CPU 1211C DC/DC/Rly (6ES7211-1HE40-0XB0) | ||
| SIMATIC Drive Controller CPU 1507D TF (6ES7615-7DF10-0AB0) | ||
| SIMATIC ET 200SP CPU 1512SP F-1 PN (6ES7512-1SM03-0AB0) | ||
| SIMATIC ET 200SP CPU 1510SP-1 PN (6ES7510-1DJ01-0AB0) | ||
| SIMATIC ET 200SP CPU 1514SPT F-2 PN (6ES7514-2WN03-0AB0) | ||
| SIMATIC ET 200SP CPU 1512SP F-1 PN (6ES7512-1SK01-0AB0) | ||
| SIMATIC ET 200SP CPU 1510SP-1 PN (6ES7510-1DK03-0AB0) | ||
| SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) V3 CPUs - Industrial OS | ||
| SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) V2 CPUs - Windows OS | ||
| SIMATIC ET 200SP CPU 1512SP-1 PN (6ES7512-1DM03-0AB0) | ||
| SIMATIC ET 200SP CPU 1514SPT-2 PN (6ES7514-2VN03-0AB0) | ||
| SIMATIC ET 200SP CPU 1512SP-1 PN (6ES7512-1DK01-0AB0) | ||
| SIMATIC S7-1200 CPU 1211C DC/DC/DC (6ES7211-1AE40-0XB0) |
Timeline
- Oct 8, 2024 CVE Published
- Oct 14, 2025 CVE Updated
References
- https://cert-portal.siemens.com/productcert/csaf/ssa-876787.json advisory
- https://cert-portal.siemens.com/productcert/html/ssa-876787.html advisory
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-284-01.json advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-24-284-01 advisory
- https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01 url
- https://www.cisa.gov/resources-tools/resources/ics-recommended-practices url
- https://www.cisa.gov/topics/industrial-control-systems url
- https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf url
- https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf url
- https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b url
- https://support.industry.siemens.com/cs/ww/en/view/109478459/ fix
- https://support.industry.siemens.com/cs/ww/en/view/109478528/ fix
- https://support.industry.siemens.com/cs/ww/en/view/109759122/ fix
- https://support.industry.siemens.com/cs/ww/en/view/109773914/ fix
- https://support.industry.siemens.com/cs/ww/en/view/107539610/ fix
- https://support.industry.siemens.com/cs/ww/en/view/109963863/ fix