First published: Tue Jan 14 2025(Updated: )
A vulnerability has been identified in SIMATIC S7-1200 CPU 1211C AC/DC/Rly (6ES7211-1BE40-0XB0), SIMATIC S7-1200 CPU 1211C DC/DC/DC (6ES7211-1AE40-0XB0), SIMATIC S7-1200 CPU 1211C DC/DC/Rly (6ES7211-1HE40-0XB0), SIMATIC S7-1200 CPU 1212C AC/DC/Rly (6ES7212-1BE40-0XB0), SIMATIC S7-1200 CPU 1212C DC/DC/DC (6ES7212-1AE40-0XB0), SIMATIC S7-1200 CPU 1212C DC/DC/Rly (6ES7212-1HE40-0XB0), SIMATIC S7-1200 CPU 1212FC DC/DC/DC (6ES7212-1AF40-0XB0), SIMATIC S7-1200 CPU 1212FC DC/DC/Rly (6ES7212-1HF40-0XB0), SIMATIC S7-1200 CPU 1214C AC/DC/Rly (6ES7214-1BG40-0XB0), SIMATIC S7-1200 CPU 1214C DC/DC/DC (6ES7214-1AG40-0XB0), SIMATIC S7-1200 CPU 1214C DC/DC/Rly (6ES7214-1HG40-0XB0), SIMATIC S7-1200 CPU 1214FC DC/DC/DC (6ES7214-1AF40-0XB0), SIMATIC S7-1200 CPU 1214FC DC/DC/Rly (6ES7214-1HF40-0XB0), SIMATIC S7-1200 CPU 1215C AC/DC/Rly (6ES7215-1BG40-0XB0), SIMATIC S7-1200 CPU 1215C DC/DC/DC (6ES7215-1AG40-0XB0), SIMATIC S7-1200 CPU 1215C DC/DC/Rly (6ES7215-1HG40-0XB0), SIMATIC S7-1200 CPU 1215FC DC/DC/DC (6ES7215-1AF40-0XB0), SIMATIC S7-1200 CPU 1215FC DC/DC/Rly (6ES7215-1HF40-0XB0), SIMATIC S7-1200 CPU 1217C DC/DC/DC (6ES7217-1AG40-0XB0), SIPLUS S7-1200 CPU 1212 AC/DC/RLY (6AG1212-1BE40-2XB0), SIPLUS S7-1200 CPU 1212 AC/DC/RLY (6AG1212-1BE40-4XB0), SIPLUS S7-1200 CPU 1212 DC/DC/RLY (6AG1212-1HE40-2XB0), SIPLUS S7-1200 CPU 1212 DC/DC/RLY (6AG1212-1HE40-4XB0), SIPLUS S7-1200 CPU 1212C DC/DC/DC (6AG1212-1AE40-2XB0), SIPLUS S7-1200 CPU 1212C DC/DC/DC (6AG1212-1AE40-4XB0), SIPLUS S7-1200 CPU 1212C DC/DC/DC RAIL (6AG2212-1AE40-1XB0), SIPLUS S7-1200 CPU 1214 AC/DC/RLY (6AG1214-1BG40-2XB0), SIPLUS S7-1200 CPU 1214 AC/DC/RLY (6AG1214-1BG40-4XB0), SIPLUS S7-1200 CPU 1214 AC/DC/RLY (6AG1214-1BG40-5XB0), SIPLUS S7-1200 CPU 1214 DC/DC/DC (6AG1214-1AG40-2XB0), SIPLUS S7-1200 CPU 1214 DC/DC/DC (6AG1214-1AG40-4XB0), SIPLUS S7-1200 CPU 1214 DC/DC/DC (6AG1214-1AG40-5XB0), SIPLUS S7-1200 CPU 1214 DC/DC/RLY (6AG1214-1HG40-2XB0), SIPLUS S7-1200 CPU 1214 DC/DC/RLY (6AG1214-1HG40-4XB0), SIPLUS S7-1200 CPU 1214 DC/DC/RLY (6AG1214-1HG40-5XB0), SIPLUS S7-1200 CPU 1214C DC/DC/DC RAIL (6AG2214-1AG40-1XB0), SIPLUS S7-1200 CPU 1214FC DC/DC/DC (6AG1214-1AF40-5XB0), SIPLUS S7-1200 CPU 1214FC DC/DC/RLY (6AG1214-1HF40-5XB0), SIPLUS S7-1200 CPU 1215 AC/DC/RLY (6AG1215-1BG40-2XB0), SIPLUS S7-1200 CPU 1215 AC/DC/RLY (6AG1215-1BG40-4XB0), SIPLUS S7-1200 CPU 1215 AC/DC/RLY (6AG1215-1BG40-5XB0), SIPLUS S7-1200 CPU 1215 DC/DC/DC (6AG1215-1AG40-2XB0), SIPLUS S7-1200 CPU 1215 DC/DC/DC (6AG1215-1AG40-4XB0), SIPLUS S7-1200 CPU 1215 DC/DC/RLY (6AG1215-1HG40-2XB0), SIPLUS S7-1200 CPU 1215 DC/DC/RLY (6AG1215-1HG40-4XB0), SIPLUS S7-1200 CPU 1215 DC/DC/RLY (6AG1215-1HG40-5XB0), SIPLUS S7-1200 CPU 1215C DC/DC/DC (6AG1215-1AG40-5XB0), SIPLUS S7-1200 CPU 1215FC DC/DC/DC (6AG1215-1AF40-5XB0). The web interface of the affected devices is vulnerable to Cross-Site Request Forgery (CSRF) attacks. This could allow an unauthenticated attacker to change the CPU mode by tricking a legitimate and authenticated user with sufficient permissions on the target CPU to click on a malicious link.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens SIMATIC S7-1200 CPU 1211C AC/DC/Rly | ||
Siemens SIMATIC S7-1200 CPU 1211C DC/DC/DC | ||
Siemens SIMATIC S7-1200 CPU 1211C DC/DC/Rly | ||
Siemens SIMATIC S7-1200 CPU 1212C AC/DC/Rly | ||
Siemens SIMATIC S7-1200 CPU 1212C DC/DC/DC | ||
Siemens SIMATIC S7-1200 CPU 1212C DC/DC/Rly | ||
Siemens SIMATIC S7-1200 CPU 1212FC DC/DC/DC | ||
Siemens SIMATIC S7-1200 CPU 1212FC DC/DC/Rly | ||
Siemens SIMATIC S7-1200 CPU 1214C AC/DC/Rly | ||
Siemens SIMATIC S7-1200 CPU 1214C DC/DC/DC | ||
Siemens SIMATIC S7-1200 CPU 1214C DC/DC/Rly | ||
Siemens SIMATIC S7-1200 CPU 1214FC DC/DC/DC | ||
Siemens SIMATIC S7-1200 CPU 1214FC DC/DC/Rly | ||
Siemens SIMATIC S7-1200 CPU 1215C AC/DC/Rly | ||
Siemens SIMATIC S7-1200 CPU 1215C DC/DC/DC | ||
Siemens SIMATIC S7-1200 CPU 1215C DC/DC/Rly | ||
Siemens SIMATIC S7-1200 CPU 1215FC DC/DC/DC | ||
Siemens SIMATIC S7-1200 CPU 1215FC DC/DC/Rly | ||
Siemens SIMATIC S7-1200 CPU 1217C DC/DC/DC | ||
Siemens SIPLUS S7-1200 CPU 1212 AC/DC/RLY | ||
Siemens SIPLUS S7-1200 CPU 1212 DC/DC/RLY | ||
Siemens SIPLUS S7-1200 CPU 1212C DC/DC/DC | ||
Siemens SIPLUS S7-1200 CPU 1212C DC/DC/DC RAIL | ||
Siemens SIPLUS S7-1200 CPU 1214 AC/DC/RLY | ||
Siemens SIPLUS S7-1200 CPU 1214 DC/DC/DC | ||
Siemens SIPLUS S7-1200 CPU 1214FC DC/DC/RLY | ||
Siemens SIPLUS S7-1200 CPU 1214C DC/DC/DC RAIL | ||
Siemens SIPLUS S7-1200 CPU 1214FC DC/DC/DC | ||
Siemens SIPLUS S7-1200 CPU 1214FC DC/DC/RLY | ||
Siemens SIPLUS S7-1200 CPU 1215 AC/DC/RLY | ||
Siemens SIPLUS S7-1200 CPU 1215C DC/DC/DC | ||
Siemens SIPLUS S7-1200 CPU 1215 DC/DC/RLY | ||
Siemens SIPLUS S7-1200 CPU 1215C DC/DC/DC | ||
Siemens SIPLUS S7-1200 CPU 1215FC DC/DC/DC |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-47100 has been rated with high severity due to the potential impact on the affected systems.
To fix CVE-2024-47100, users are advised to apply the latest security patches provided by Siemens for the affected SIMATIC S7-1200 CPUs.
CVE-2024-47100 affects various models of Siemens SIMATIC S7-1200 CPUs, including the 1211C, 1212C, and 1214C among others.
CVE-2024-47100 involves security issues that can be exploited to compromise the integrity and availability of the affected Siemens SIMATIC devices.
If unable to update the device, it is recommended to implement security measures such as network segmentation to mitigate the risk associated with CVE-2024-47100.