SSA-876787 PUBLISHED CVSS 4.699999809265137 MEDIUM

Several SIMATIC S7-1500 and S7-1200 CPU versions are affected by an open redirect vulnerability that could allow an attacker to make the web server of affected devices redirect a legitimate user to an attacker-chosen URL. For a successful attack, the legitimate user must actively click on an attacker-crafted link. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens recommends specific countermeasures for products where fixes are not, or not yet available.

Risk Scores

CVSS v3.1
4.699999809265137
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N

Affected Products

VendorProductVersions
SIMATIC ET 200SP CPU 1510SP F-1 PN (6ES7510-1SK03-0AB0)
SIMATIC S7-1200 CPU 1211C AC/DC/Rly (6ES7211-1BE40-0XB0)
SIMATIC ET 200SP CPU 1510SP-1 PN (6ES7510-1DJ01-0AB0)
SIMATIC ET 200SP CPU 1514SPT F-2 PN (6ES7514-2WN03-0AB0)
SIMATIC ET 200SP CPU 1510SP F-1 PN (6ES7510-1SJ01-0AB0)
SIMATIC ET 200SP CPU 1514SPT-2 PN (6ES7514-2VN03-0AB0)
SIMATIC ET 200SP CPU 1512SP F-1 PN (6ES7512-1SM03-0AB0)
SIMATIC ET 200SP CPU 1512SP-1 PN (6ES7512-1DM03-0AB0)
SIMATIC Drive Controller CPU 1504D TF (6ES7615-4DF10-0AB0)
SIMATIC ET 200SP CPU 1514SP-2 PN (6ES7514-2DN03-0AB0)
SIMATIC ET 200SP CPU 1512SP F-1 PN (6ES7512-1SK01-0AB0)
SIMATIC S7-1200 CPU 1211C DC/DC/Rly (6ES7211-1HE40-0XB0)
SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) V2 CPUs - Windows OS
SIMATIC ET 200SP CPU 1510SP-1 PN (6ES7510-1DK03-0AB0)
SIMATIC Drive Controller CPU 1507D TF (6ES7615-7DF10-0AB0)
SIMATIC ET 200SP CPU 1514SP F-2 PN (6ES7514-2SN03-0AB0)
SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) V3 CPUs - Industrial OS
SIMATIC S7-1200 CPU 1211C DC/DC/DC (6ES7211-1AE40-0XB0)
SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) V3 CPUs - Windows OS
SIMATIC ET 200SP CPU 1512SP-1 PN (6ES7512-1DK01-0AB0)

Timeline

References

Open in Interactive Console →