Siemens SIMATIC S7-1200 CSRF Vulnerability (CVE-2015-5698)
Siemens SIMATIC S7-1200 CSRF Vulnerability (CVE-2015-5698)
Release date:
Updated on:
Affected Systems:
Siemens SIMATIC S7-1200
Description:
CVE (CAN) ID: CVE-2015-5698
The SIMATIC S7-1200 is a programmable controller that enables simple but highly precise automation tasks.
Siemens SIMATIC S7-1200 CPU device, firmware versions earlier than 4.1.3, the Web server has a Cross-Site Request Forgery Vulnerability, remote attackers can exploit this vulnerability to hijack the identity of the victim verification.
<* Source: Ralf w.neberg
Maik Br ü ggann
Henderson Rik Bettermann
*>
Suggestion:
Vendor patch:
Siemens
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-134003.pdf
Https://ics-cert.us-cert.gov/advisories/ICSA-15-239-02
This article permanently updates the link address: