The Siemens SIMATIC S7-1200 2.x PLC does not properly protect the private key of the SIMATIC CONTROLLER Certification Authority certificate, which allows remote attackers to spoof the S7-1200 web server by using this key to create a forged certificate.
References
Link | Resource |
---|---|
http://en.securitylab.ru/lab/PT-2012-48 | Third Party Advisory |
http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-240718.pdf | Broken Link Vendor Advisory |
http://www.us-cert.gov/control_systems/pdf/ICSA-12-263-01.pdf | Broken Link Third Party Advisory US Government Resource |
http://en.securitylab.ru/lab/PT-2012-48 | Third Party Advisory |
http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-240718.pdf | Broken Link Vendor Advisory |
http://www.us-cert.gov/control_systems/pdf/ICSA-12-263-01.pdf | Broken Link Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
History
21 Nov 2024, 01:40
Type | Values Removed | Values Added |
---|---|---|
References | () http://en.securitylab.ru/lab/PT-2012-48 - Third Party Advisory | |
References | () http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-240718.pdf - Broken Link, Vendor Advisory | |
References | () http://www.us-cert.gov/control_systems/pdf/ICSA-12-263-01.pdf - Broken Link, Third Party Advisory, US Government Resource |
01 Feb 2022, 14:58
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-310 |
CWE-295 |
CVSS |
v2 : v3 : |
v2 : 4.3
v3 : unknown |
References | (MISC) http://www.us-cert.gov/control_systems/pdf/ICSA-12-263-01.pdf - Broken Link, Third Party Advisory, US Government Resource | |
References | (CONFIRM) http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-240718.pdf - Broken Link, Vendor Advisory | |
References | (MISC) http://en.securitylab.ru/lab/PT-2012-48 - Third Party Advisory | |
CPE | cpe:2.3:h:siemens:simatic_s7-1200_plc:2.0:*:*:*:*:*:*:* cpe:2.3:h:siemens:simatic_s7-1200_plc:2.2:*:*:*:*:*:*:* |
cpe:2.3:o:siemens:simatic_s7-1200_cpu_1212fc_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:siemens:simatic_s7-1200_cpu_1212c:-:*:*:*:*:*:*:* cpe:2.3:h:siemens:simatic_s7-1200_cpu_1212fc:-:*:*:*:*:*:*:* cpe:2.3:h:siemens:simatic_s7-1200_cpu_1211c:-:*:*:*:*:*:*:* cpe:2.3:h:siemens:simatic_s7-1200_cpu_1214c:-:*:*:*:*:*:*:* cpe:2.3:h:siemens:simatic_s7-1200_cpu_1214_fc:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:simatic_s7-1200_cpu_1212c_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:siemens:simatic_s7-1200_cpu_1215c_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:siemens:simatic_s7-1200_cpu_1215_fc:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:simatic_s7-1200_cpu_1214_fc_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:siemens:simatic_s7-1200_cpu_1211c_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:siemens:simatic_s7-1200_cpu_1214c_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:siemens:simatic_s7-1200_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:siemens:simatic_s7-1200_cpu_1217c:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:simatic_s7-1200_cpu_1217c_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:siemens:simatic_s7-1200:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:simatic_s7-1200_cpu_1215_fc_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:siemens:simatic_s7-1200_cpu_1215c:-:*:*:*:*:*:*:* |
Information
Published : 2012-09-25 11:07
Updated : 2025-04-11 00:51
NVD link : CVE-2012-3037
Mitre link : CVE-2012-3037
CVE.ORG link : CVE-2012-3037
JSON object : View
Products Affected
siemens
- simatic_s7-1200_cpu_1212fc
- simatic_s7-1200_cpu_1211c
- simatic_s7-1200_cpu_1214_fc_firmware
- simatic_s7-1200_cpu_1212c
- simatic_s7-1200_cpu_1215_fc_firmware
- simatic_s7-1200_cpu_1215_fc
- simatic_s7-1200_cpu_1211c_firmware
- simatic_s7-1200_cpu_1215c
- simatic_s7-1200
- simatic_s7-1200_firmware
- simatic_s7-1200_cpu_1214c_firmware
- simatic_s7-1200_cpu_1217c
- simatic_s7-1200_cpu_1212fc_firmware
- simatic_s7-1200_cpu_1214_fc
- simatic_s7-1200_cpu_1212c_firmware
- simatic_s7-1200_cpu_1214c
- simatic_s7-1200_cpu_1217c_firmware
- simatic_s7-1200_cpu_1215c_firmware
CWE
CWE-295
Improper Certificate Validation