Siemens SIMATIC S7-1200 SSL Private Key Reuse Spoofing Vulnerability
BID:55559
Info
Siemens SIMATIC S7-1200 SSL Private Key Reuse Spoofing Vulnerability
| Bugtraq ID: | 55559 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 13 2012 12:00AM |
| Updated: | Sep 13 2012 12:00AM |
| Credit: | Dmitry Sklyarov from Positive Technologies |
| Vulnerable: |
Siemens SIMATIC S7-1200 2.0.3 Siemens SIMATIC S7-1200 2.0.2 |
| Not Vulnerable: | |
Discussion
Siemens SIMATIC S7-1200 SSL Private Key Reuse Spoofing Vulnerability
Siemens SIMATIC S7-1200 is prone to a security vulnerability that may allow attackers to spoof SSL certificates.
Attackers can exploit this issue to display incorrect SSL certificates. Successful exploits will cause victims to accept the certificates assuming they are from a legitimate site.
Siemens SIMATIC S7-1200 versions 2.x are vulnerable; other versions may also be affected.
Siemens SIMATIC S7-1200 is prone to a security vulnerability that may allow attackers to spoof SSL certificates.
Attackers can exploit this issue to display incorrect SSL certificates. Successful exploits will cause victims to accept the certificates assuming they are from a legitimate site.
Siemens SIMATIC S7-1200 versions 2.x are vulnerable; other versions may also be affected.
Exploit / POC
Siemens SIMATIC S7-1200 SSL Private Key Reuse Spoofing Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
Siemens SIMATIC S7-1200 SSL Private Key Reuse Spoofing Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Siemens SIMATIC S7-1200 SSL Private Key Reuse Spoofing Vulnerability
References:
References:
- Siemens Homepage (Siemens)