Release date:
Updated on:
Affected Systems:
Siemens SIMATIC S7-1200
Description:
--------------------------------------------------------------------------------
Bugtraq id: 66346
CVE (CAN) ID: CVE-2014-2250
The SIMATIC S7-1200 is a programmable controller that enables simple but highly precise automation tasks.
SIMATIC S7-1200 versions earlier than 4.0 have security vulnerabilities in implementation, due to low entropy in the random number generator, integrated Web server authentication method (port 80/tcp and port 443/tcp) when the session token is predictable, attackers can hijack Web sessions on the network.
<* Source: vendor
Link: http://www.securelist.com/en/advisories/57441
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Siemens
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-654382.pdf