CVE-2014-2247
published 2014-03-16CVE-2014-2247: The integrated web server on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allows remote attackers to inject headers via unspecified…
PriorityP428medium5.8CVSS 2.0
AVNACMAuNCNIPAP
EPSS
2.42%
82.2th percentile
The integrated web server on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allows remote attackers to inject headers via unspecified vectors.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | simatic_s7-1500_cpu_firmware | <= 1.1.2 | — |
| siemens | simatic_s7-1500_cpu_firmware | — | — |
| siemens | simatic_s7-1500_cpu_firmware | — | — |
| siemens | simatic_s7-1500_cpu_firmware | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r54v-r859-38g3: The integrated web server on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1
ghsa_unreviewed·2022-05-13
CVE-2014-2247 [MEDIUM] GHSA-r54v-r859-38g3: The integrated web server on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1
The integrated web server on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allows remote attackers to inject headers via unspecified vectors.
CISA ICS
Siemens SIMATIC S7-1500 CPU Firmware Vulnerabilities
cisa_ics·2018-09-06
Siemens SIMATIC S7-1500 CPU Firmware Vulnerabilities
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU Firmware Vulnerabilities
Last RevisedSeptember 06, 2018
Alert CodeICSA-14-073-01
## OVERVIEW
Siemens and Positive Technology researchers (Yury Goltsev, Llya Karpov, Alexey Osipov, Dmitry Serebryannikov and Alex Timorin) have identified nine firmware vulnerabilities in the Siemens SIMATIC S7-1500 CPU Firmware. Siemens has produced a patch that mitigates these vulnerabilities.
These vulnerabilities could be exploited remotely.
## AFFECTED PRODUCTS
The following SIMATIC S7-1500 versions are affected:
- SIMATIC S7-1500 CPU family, all versions older t
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://ics-cert.us-cert.gov/advisories/ICSA-14-073-01http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-456423.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-456423.pdfhttp://ics-cert.us-cert.gov/advisories/ICSA-14-073-01http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-456423.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-456423.pdf
2014-03-16
Published