First published: Fri Apr 25 2014(Updated: )
CRLF injection vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices 2.x and 3.x allows remote attackers to inject arbitrary HTTP headers via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens SIMATIC S7-1200 CPU | =2.0 | |
Siemens SIMATIC S7-1200 CPU | =3.0 | |
Siemens SIMATIC S7-1200 CPU | =3.0.2 | |
Siemens CPU 1211C | ||
Siemens CPU 1212C | ||
Siemens SIMATIC S7-1200 CPU 1214C | ||
Siemens CPU 1215C | ||
Siemens CPU 1217C |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2909 is classified with a Medium severity level, indicating a moderate security risk.
To remediate CVE-2014-2909, updating the firmware of the affected Siemens SIMATIC S7-1200 CPU devices to the latest version is recommended.
CVE-2014-2909 affects Siemens SIMATIC S7-1200 CPU devices running firmware versions 2.x and 3.x.
Yes, CVE-2014-2909 allows remote attackers to inject arbitrary HTTP headers, potentially leading to further attacks.
CRLF injection in CVE-2014-2909 refers to the ability to insert carriage return and line feed characters into HTTP headers, which can manipulate server responses.