Insufficient Entropy in Siemens SIMATIC S7-1200 CPU PLC Devices
CVE-2014-2250

Currently unrated

Key Information:

Summary

The random-number generator in Siemens SIMATIC S7-1200 CPU PLC devices with firmware versions prior to 4.0 suffers from insufficient entropy. This flaw can be exploited by remote attackers to bypass cryptographic protections, potentially enabling session hijacking and other malicious activities through unspecified attack vectors. This vulnerability is distinct from similar issues, emphasizing the need for updated firmware to mitigate risks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.