Cross-site Scripting Vulnerability in Siemens SIMATIC S7-1500 PLC
CVE-2014-2246
Currently unrated
Summary
The integrated web server on Siemens SIMATIC S7-1500 CPU PLC devices is vulnerable to cross-site scripting (XSS), which allows remote attackers to inject arbitrary web scripts or HTML. This can be exploited through unspecified vectors, potentially compromising the security of the device and the broader ecosystem. Organizations using these PLCs should assess their firmware version and apply any necessary security patches to mitigate risks associated with this vulnerability.
References
Timeline
Vulnerability published
Vulnerability Reserved