CVE-2015-5698: CSRF
Published Aug 30, 2015
·Updated
Cross-site request forgery (CSRF) vulnerability in the web server on Siemens SIMATIC S7-1200 CPU devices with firmware before 4.1.3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
Affected Software
2 affected components
Siemens Simatic S7 1200 Cpu Firmware<=4.1.2
Siemens Simatic S7 1200 Cpu
Remediation
Event History
Aug 30, 2015
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5698?
CVE-2015-5698 is classified as a high severity vulnerability due to its potential to allow attackers to hijack authentication.
2
Which Siemens devices are affected by CVE-2015-5698?
CVE-2015-5698 affects Siemens SIMATIC S7-1200 CPU devices running firmware versions prior to 4.1.3.
3
How do I fix CVE-2015-5698?
To mitigate CVE-2015-5698, update the Siemens SIMATIC S7-1200 CPU firmware to version 4.1.3 or later.
4
What type of vulnerability is CVE-2015-5698?
CVE-2015-5698 is a Cross-site Request Forgery (CSRF) vulnerability.
5
What can attackers achieve by exploiting CVE-2015-5698?
Attackers can hijack the authentication of unspecified victims by exploiting CVE-2015-5698.