CVE-2012-3037
published 2012-09-25CVE-2012-3037: The Siemens SIMATIC S7-1200 2.x PLC does not properly protect the private key of the SIMATIC CONTROLLER Certification Authority certificate, which allows…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.47%
70.7th percentile
The Siemens SIMATIC S7-1200 2.x PLC does not properly protect the private key of the SIMATIC CONTROLLER Certification Authority certificate, which allows remote attackers to spoof the S7-1200 web server by using this key to create a forged certificate.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | simatic_s7-1200_cpu_1211c_firmware | >= 2.0.0 < 3.0.0 | 3.0.0 |
| siemens | simatic_s7-1200_cpu_1212c_firmware | >= 2.0.0 < 3.0.0 | 3.0.0 |
| siemens | simatic_s7-1200_cpu_1212fc_firmware | >= 2.0.0 < 3.0.0 | 3.0.0 |
| siemens | simatic_s7-1200_cpu_1214_fc_firmware | >= 2.0.0 < 3.0.0 | 3.0.0 |
| siemens | simatic_s7-1200_cpu_1214c_firmware | >= 2.0.0 < 3.0.0 | 3.0.0 |
| siemens | simatic_s7-1200_cpu_1215_fc_firmware | >= 2.0.0 < 3.0.0 | 3.0.0 |
| siemens | simatic_s7-1200_cpu_1215c_firmware | >= 2.0.0 < 3.0.0 | 3.0.0 |
| siemens | simatic_s7-1200_cpu_1217c_firmware | >= 2.0.0 < 3.0.0 | 3.0.0 |
| siemens | simatic_s7-1200_firmware | >= 2.0.0 < 3.0.0 | 3.0.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cq39-26j4-6jcj: The Siemens SIMATIC S7-1200 2
ghsa_unreviewed·2022-05-13
CVE-2012-3037 [MEDIUM] CWE-295 GHSA-cq39-26j4-6jcj: The Siemens SIMATIC S7-1200 2
The Siemens SIMATIC S7-1200 2.x PLC does not properly protect the private key of the SIMATIC CONTROLLER Certification Authority certificate, which allows remote attackers to spoof the S7-1200 web server by using this key to create a forged certificate.
CISA ICS
Siemens S7-1200 Insecure Storage of HTTPS CA Certificate
cisa_ics·2013-05-06
Siemens S7-1200 Insecure Storage of HTTPS CA Certificate
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens S7-1200 Insecure Storage of HTTPS CA Certificate
Last RevisedMay 06, 2013
Alert CodeICSA-12-263-01
## Overview
Siemens has reportedSSA-240718, http://www.siemens.com/corporate-technology/en/research-areas/siemens-cert-security-advisories.htm, Web site last accessed September 19, 2012 an insecure HTTPS certificate storage vulnerability in Siemens’ S7-1200 v2.x. Siemens has provided guidance to mitigate this vulnerability. This vulnerability could be exploited remotely.
## Affected Products
Siemens reports that the vulnerability affects the following products:
- SIMATIC
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://en.securitylab.ru/lab/PT-2012-48http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-240718.pdfhttp://www.us-cert.gov/control_systems/pdf/ICSA-12-263-01.pdfhttp://en.securitylab.ru/lab/PT-2012-48http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-240718.pdfhttp://www.us-cert.gov/control_systems/pdf/ICSA-12-263-01.pdf
2012-09-25
Published