Release date:
Updated on:
Affected Systems:
Siemens SIMATIC S7-1500
Description:
--------------------------------------------------------------------------------
Bugtraq id: 66199
CVE (CAN) ID: CVE-2014-2249
Siemens SIMATIC S7-1500 is a modular controller series product.
Siemens SIMATIC S7-1500 versions earlier than 1.5.0 did not properly verify HTTP requests, there is a cross-site Request Forgery Vulnerability in implementation, successful exploitation can lead to the execution of some administrator operations are not authorized to access the affected applications.
<* Source: Dmitry Serebryannikov
Ilya Karpov
Alexey Osipov
Link: http://secunia.com/advisories/57400
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Siemens
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.siemens.com/corporate-technology/pool/
Http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-456423.pdf