Cross-site scripting (XSS) vulnerability in the web server on Siemens SIMATIC S7-1200 PLCs 2.x through 3.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URI.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Siemens
Subscribe
|
Simatic S7-1200
Subscribe
Simatic S7-1200 Cpu 1211c
Subscribe
Simatic S7-1200 Cpu 1211c Firmware
Subscribe
Simatic S7-1200 Cpu 1212c
Subscribe
Simatic S7-1200 Cpu 1212c Firmware
Subscribe
Simatic S7-1200 Cpu 1212fc
Subscribe
Simatic S7-1200 Cpu 1212fc Firmware
Subscribe
Simatic S7-1200 Cpu 1214 Fc
Subscribe
Simatic S7-1200 Cpu 1214 Fc Firmware
Subscribe
Simatic S7-1200 Cpu 1214c
Subscribe
Simatic S7-1200 Cpu 1214c Firmware
Subscribe
Simatic S7-1200 Cpu 1215 Fc
Subscribe
Simatic S7-1200 Cpu 1215 Fc Firmware
Subscribe
Simatic S7-1200 Cpu 1215c
Subscribe
Simatic S7-1200 Cpu 1215c Firmware
Subscribe
Simatic S7-1200 Cpu 1217c
Subscribe
Simatic S7-1200 Cpu 1217c Firmware
Subscribe
Simatic S7-1200 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2012-3018 | Cross-site scripting (XSS) vulnerability in the web server on Siemens SIMATIC S7-1200 PLCs 2.x through 3.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URI. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-05-23T18:26:17.632Z
Reserved: 2012-05-30T00:00:00.000Z
Link: CVE-2012-3040
No data.
Status : Deferred
Published: 2012-10-10T18:55:02.080
Modified: 2025-04-11T00:51:21.963
Link: CVE-2012-3040
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD