Siemens SIMATIC S7-1200 CPUs Cross-Site Request Forgery Vulnerability

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the web interface of SIMATIC S7-1200 CPUs prior to version 4.7, including SIPLUS variants. This vulnerability allows an unauthenticated attacker to manipulate the CPU mode by deceiving a legitimate user with the necessary permissions to click on a malicious link.

Impact

Exploitation of this vulnerability could lead to unauthorized changes in the CPU mode, potentially disrupting operations or causing unintended behavior in automated processes.

Remediation

Users are advised to update to version 4.7 or later. Specific product remediations can be found in the Siemens Security Advisory SSA-717113.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
0.6
exploitability
6.0
remediation
7.9
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.