Siemens SIMATIC S7-1500 CVE-2014-2247 HTTP Response Splitting Vulnerability
BID:66185
Info
Siemens SIMATIC S7-1500 CVE-2014-2247 HTTP Response Splitting Vulnerability
| Bugtraq ID: | 66185 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2247 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 13 2014 12:00AM |
| Updated: | Mar 19 2014 02:03AM |
| Credit: | Dmitry Serebryannikov, Ilya Karpov, Alexey Osipov, Yury Goltsev, Alex Timorin, Alexey Osipov, Ilya Karpov from Positive Technologies |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Siemens SIMATIC S7-1500 CVE-2014-2247 HTTP Response Splitting Vulnerability
Siemens SIMATIC S7-1500 is prone to an HTTP response-splitting vulnerability.
Attackers can leverage this issue to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that try to entice client users into having a false sense of trust.
Versions prior to SIMATIC S7-1500 1.5.0 are vulnerable.
Siemens SIMATIC S7-1500 is prone to an HTTP response-splitting vulnerability.
Attackers can leverage this issue to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that try to entice client users into having a false sense of trust.
Versions prior to SIMATIC S7-1500 1.5.0 are vulnerable.
Exploit / POC
Siemens SIMATIC S7-1500 CVE-2014-2247 HTTP Response Splitting Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
Siemens SIMATIC S7-1500 CVE-2014-2247 HTTP Response Splitting Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Siemens SIMATIC S7-1500 CVE-2014-2247 HTTP Response Splitting Vulnerability
References:
References: