Siemens SIMATIC S7-1200 CPU V1
cpe:2.3:h:siemens:simatic_s7-1200:*:*:*:*:*:*:*, +7 more
- < V2.0.3
A denial-of-service vulnerability has been identified in Siemens SIMATIC S7-1200 CPU V1 and V2 families, including SIPLUS variants, all versions prior to V2.0.3. The issue arises because the web server interface improperly handles incoming malformed HTTP traffic at a high rate. This flaw could enable an unauthenticated remote attacker to force the device into a stop or defect state, creating a denial-of-service condition.
Exploitation of this vulnerability causes the device to enter a stop or defect state, disrupting normal operations and communication.
Siemens recommends updating to the latest version. If an update is not possible, the web server can be disabled, if feasible.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.