CVE-2012-3040
10.10.2012, 18:55
Cross-site scripting (XSS) vulnerability in the web server on Siemens SIMATIC S7-1200 PLCs 2.x through 3.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URI.
Vendor | Product | Version |
---|---|---|
siemens | simatic_s7-1200_firmware | 2.0.0 ≤ 𝑥 < 3.0.2 |
siemens | simatic_s7-1200_cpu_1211c_firmware | 2.0.0 ≤ 𝑥 < 3.0.2 |
siemens | simatic_s7-1200_cpu_1212c_firmware | 2.0.0 ≤ 𝑥 < 3.0.2 |
siemens | simatic_s7-1200_cpu_1212fc_firmware | 2.0.0 ≤ 𝑥 < 3.0.2 |
siemens | simatic_s7-1200_cpu_1214_fc_firmware | 2.0.0 ≤ 𝑥 < 3.0.2 |
siemens | simatic_s7-1200_cpu_1214c_firmware | 2.0.0 ≤ 𝑥 < 3.0.2 |
siemens | simatic_s7-1200_cpu_1215_fc_firmware | 2.0.0 ≤ 𝑥 < 3.0.2 |
siemens | simatic_s7-1200_cpu_1215c_firmware | 2.0.0 ≤ 𝑥 < 3.0.2 |
siemens | simatic_s7-1200_cpu_1217c_firmware | 2.0.0 ≤ 𝑥 < 3.0.2 |
𝑥
= Vulnerable software versions
References