Cross-site Scripting Vulnerability in Siemens SIMATIC S7-1500 PLC
CVE-2014-2246

Currently unrated

Key Information:

Vendor
Siemens
Vendor
CVE Published:
16 March 2014

Summary

The integrated web server on Siemens SIMATIC S7-1500 CPU PLC devices is vulnerable to cross-site scripting (XSS), which allows remote attackers to inject arbitrary web scripts or HTML. This can be exploited through unspecified vectors, potentially compromising the security of the device and the broader ecosystem. Organizations using these PLCs should assess their firmware version and apply any necessary security patches to mitigate risks associated with this vulnerability.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.