CVE-2012-3037: Medium severity siemens simatic s7-1200 cpu vulnerability
The Siemens SIMATIC S7-1200 2.x PLC does not properly protect the private key of the SIMATIC CONTROLLER Certification Authority certificate, which allows remote attackers to spoof the S7-1200 web server by using this key to create a forged certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-3037?
CVE-2012-3037 has a high severity due to the potential for remote attackers to spoof the S7-1200 web server.
How do I fix CVE-2012-3037?
To fix CVE-2012-3037, update the SIMATIC S7-1200 firmware to a version higher than 3.0.0.
What systems are affected by CVE-2012-3037?
CVE-2012-3037 affects Siemens SIMATIC S7-1200 PLC firmware versions 2.x, specifically versions from 2.0.0 to 3.0.0.
What type of attack can occur with CVE-2012-3037?
CVE-2012-3037 can allow attackers to create forged certificates, enabling them to impersonate the S7-1200 web server.
Is CVE-2012-3037 a hardware or software vulnerability?
CVE-2012-3037 is a software vulnerability related to the improper protection of private keys in firmware.