QID 590992
Date Published: 2022-08-24
QID 590992: Siemens S7-1200 Web Application Cross-Site Scripting (XSS) Vulnerability (ICSA-12-283-01) (SSA-279823)
Affected Products
Siemens reports that the vulnerabilities affect the following versions of S7-1200 PLCs:
V2.x,
V3.0.0, and
V3.0.1.
Impact
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
An attacker that successfully exploits this vulnerability can run malicious JavaScript code on the target machine. Malicious code can execute various actions such as modify browser contents delivered from the PLC, steal session data, and issue commands from the PLCs Web server.
Solution
Customers are advised to refer to CERT MITIGATIONS section ICSA-12-283-01 for affected packages and patching details.
Vendor References
- ICSA-12-283-01 -
www.us-cert.gov/ics/advisories/ICSA-12-283-01
CVEs related to QID 590992
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSA-12-283-01 |
|