CVE-2012-3040
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD
Description
Cross-site scripting (XSS) vulnerability in the web server on Siemens SIMATIC S7-1200 PLCs 2.x through 3.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URI.
Affected (9)
Products: Siemens: Simatic S7 1200 Firmware, Simatic S7 1200 Cpu 1211c Firmware, Simatic S7 1200 Cpu 1212c Firmware, Simatic S7 1200 Cpu 1212fc Firmware, Simatic S7 1200 Cpu 1214 Fc Firmware, Simatic S7 1200 Cpu 1214c Firmware, Simatic S7 1200 Cpu 1215 Fc Firmware, Simatic S7 1200 Cpu 1215c Firmware, Simatic S7 1200 Cpu 1217c Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.0.0 to 3.0.2 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 1200 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.0.0 to 3.0.2 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 1200 Cpu 1211c | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.0.0 to 3.0.2 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 1200 Cpu 1212c | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.0.0 to 3.0.2 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 1200 Cpu 1212fc | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.0.0 to 3.0.2 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 1200 Cpu 1214 Fc | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.0.0 to 3.0.2 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 1200 Cpu 1214c | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.0.0 to 3.0.2 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 1200 Cpu 1215 Fc | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.0.0 to 3.0.2 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 1200 Cpu 1215c | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.0.0 to 3.0.2 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic S7 1200 Cpu 1217c | All versions |
References (10)
Source: ics-cert@hq.dhs.gov
Broken LinkVendor Advisory
Source: ics-cert@hq.dhs.gov
Broken LinkThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryUS Government Resource
Timeline
No history available yet.