CVE-2012-3040: XSS
Published Oct 10, 2012
·Updated
Cross-site scripting (XSS) vulnerability in the web server on Siemens SIMATIC S7-1200 PLCs 2.x through 3.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URI.
Affected Software
18 affected components
Siemens Simatic S7-1200 Firmware>=2.0.0<3.0.2
Siemens SIMATIC S7-1200
Siemens Simatic S7-1200 Cpu 1211c Firmware>=2.0.0<3.0.2
Siemens Simatic S7-1200 Cpu 1211c
Siemens Simatic S7-1200 Cpu 1212c Firmware>=2.0.0<3.0.2
Siemens Simatic S7-1200 Cpu 1212c
Siemens Simatic S7-1200 Cpu 1212fc Firmware>=2.0.0<3.0.2
Siemens Simatic S7-1200 Cpu 1212fc
Siemens Simatic S7-1200 Cpu 1214 Fc Firmware>=2.0.0<3.0.2
Siemens Simatic S7-1200 Cpu 1214 Fc
Siemens Simatic S7-1200 Cpu 1214c Firmware>=2.0.0<3.0.2
Siemens Simatic S7-1200 Cpu 1214c
Siemens Simatic S7-1200 Cpu 1215 Fc Firmware>=2.0.0<3.0.2
Siemens Simatic S7-1200 Cpu 1215 Fc
Siemens Simatic S7-1200 Cpu 1215c Firmware>=2.0.0<3.0.2
Siemens Simatic S7-1200 Cpu 1215c
Siemens Simatic S7-1200 Cpu 1217c Firmware>=2.0.0<3.0.2
Siemens Simatic S7-1200 Cpu 1217c
Event History
Oct 10, 2012
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-3040?
CVE-2012-3040 is considered a medium-severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2012-3040?
To fix CVE-2012-3040, upgrade to a firmware version for the Siemens SIMATIC S7-1200 PLC that is higher than 3.0.2.
3
What products are affected by CVE-2012-3040?
CVE-2012-3040 affects Siemens SIMATIC S7-1200 PLCs with firmware versions 2.x up to 3.0.1.
4
What type of vulnerability is CVE-2012-3040?
CVE-2012-3040 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web script or HTML.
5
Can CVE-2012-3040 be exploited remotely?
Yes, CVE-2012-3040 can be exploited remotely by sending a crafted URI to the vulnerable web server.