Siemens SIMATIC S7-1200 CVE-2014-2909 HTTP Response Splitting Vulnerability
BID:67061
Info
Siemens SIMATIC S7-1200 CVE-2014-2909 HTTP Response Splitting Vulnerability
| Bugtraq ID: | 67061 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-2909 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 24 2014 12:00AM |
| Updated: | Apr 24 2014 12:00AM |
| Credit: | Ralf Spenneberg, Hendrik Schwartke, and Maik Brüggemann from OpenSource Training |
| Vulnerable: |
Siemens SIMATIC S7-1200 3.0.1 Siemens SIMATIC S7-1200 3.0.0 Siemens SIMATIC S7-1200 3.0 Siemens SIMATIC S7-1200 2.0.3 Siemens SIMATIC S7-1200 2.0.2 |
| Not Vulnerable: |
Siemens SIMATIC S7-1200 4.0 |
Discussion
Siemens SIMATIC S7-1200 CVE-2014-2909 HTTP Response Splitting Vulnerability
Siemens SIMATIC S7-1200 is prone to an HTTP-response-splitting vulnerability because it fails to properly sanitize user-supplied input.
Attackers can leverage this issue to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that try to entice client users into a false sense of trust.
SIMATIC S7-1200 2.x and 3.x versions are vulnerable.
Siemens SIMATIC S7-1200 is prone to an HTTP-response-splitting vulnerability because it fails to properly sanitize user-supplied input.
Attackers can leverage this issue to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that try to entice client users into a false sense of trust.
SIMATIC S7-1200 2.x and 3.x versions are vulnerable.