QID 590884
Date Published: 2022-07-18
QID 590884: Siemens SIMATIC S7-1200 V2.x Insecure storage of HTTPS CA certificate Vulnerability (SSA-240718)
AFFECTED PRODUCTS
SIMATIC S7-1200 CPU family (incl. SIPLUS variants): V2.x
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
The private key for the CA SIMATIC CONTROLLER in the S7-1200 V2.x has been compromised. This could allow an attacker to perform man-in-the-middle attacks or to deploy malicious but trusted web sites.
Solution
Customers are advised to refer to CERT MITIGATIONS section ssa-240718 for affected packages and patching details.
Vendor References
CVEs related to QID 590884
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ssa-240718 |
|