CVE-2012-3037

The Siemens SIMATIC S7-1200 2.x PLC does not properly protect the private key of the SIMATIC CONTROLLER Certification Authority certificate, which allows remote attackers to spoof the S7-1200 web server by using this key to create a forged certificate.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:siemens:simatic_s7-1200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_s7-1200:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:siemens:simatic_s7-1200_cpu_1211c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_s7-1200_cpu_1211c:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:siemens:simatic_s7-1200_cpu_1212c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_s7-1200_cpu_1212c:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:siemens:simatic_s7-1200_cpu_1212fc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_s7-1200_cpu_1212fc:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:siemens:simatic_s7-1200_cpu_1214_fc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_s7-1200_cpu_1214_fc:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:siemens:simatic_s7-1200_cpu_1214c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_s7-1200_cpu_1214c:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:siemens:simatic_s7-1200_cpu_1215_fc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_s7-1200_cpu_1215_fc:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:siemens:simatic_s7-1200_cpu_1215c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_s7-1200_cpu_1215c:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:siemens:simatic_s7-1200_cpu_1217c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_s7-1200_cpu_1217c:-:*:*:*:*:*:*:*

History

21 Nov 2024, 01:40

Type Values Removed Values Added
References () http://en.securitylab.ru/lab/PT-2012-48 - Third Party Advisory () http://en.securitylab.ru/lab/PT-2012-48 - Third Party Advisory
References () http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-240718.pdf - Broken Link, Vendor Advisory () http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-240718.pdf - Broken Link, Vendor Advisory
References () http://www.us-cert.gov/control_systems/pdf/ICSA-12-263-01.pdf - Broken Link, Third Party Advisory, US Government Resource () http://www.us-cert.gov/control_systems/pdf/ICSA-12-263-01.pdf - Broken Link, Third Party Advisory, US Government Resource

Information

Published : 2012-09-25 11:07

Updated : 2024-11-21 01:40


NVD link : CVE-2012-3037

Mitre link : CVE-2012-3037

CVE.ORG link : CVE-2012-3037


JSON object : View

Products Affected

siemens

  • simatic_s7-1200_cpu_1214c_firmware
  • simatic_s7-1200_cpu_1212fc
  • simatic_s7-1200_cpu_1215c
  • simatic_s7-1200_cpu_1215_fc_firmware
  • simatic_s7-1200_cpu_1211c_firmware
  • simatic_s7-1200_cpu_1211c
  • simatic_s7-1200_cpu_1217c
  • simatic_s7-1200_cpu_1217c_firmware
  • simatic_s7-1200_cpu_1214c
  • simatic_s7-1200_cpu_1212fc_firmware
  • simatic_s7-1200_cpu_1214_fc_firmware
  • simatic_s7-1200_cpu_1215_fc
  • simatic_s7-1200_firmware
  • simatic_s7-1200_cpu_1215c_firmware
  • simatic_s7-1200
  • simatic_s7-1200_cpu_1212c
  • simatic_s7-1200_cpu_1214_fc
  • simatic_s7-1200_cpu_1212c_firmware
CWE
CWE-295

Improper Certificate Validation