Vulnerability Description
Cross-site scripting (XSS) vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices 2.x and 3.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Simatic S7 Cpu 1200 Firmware | 2.0 |
| Siemens | Simatic S7 Cpu-1211C | - |
| Siemens | Simatic S7 Cpu 1212C | - |
| Siemens | Simatic S7 Cpu 1214C | - |
| Siemens | Simatic S7 Cpu 1215C | - |
| Siemens | Simatic S7 Cpu 1217C | - |
Related Weaknesses (CWE)
References
- http://ics-cert.us-cert.gov/advisories/ICSA-14-114-02US Government Resource
- http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_adviVendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-892012.pdf
- https://www.exploit-db.com/exploits/44687/
- http://ics-cert.us-cert.gov/advisories/ICSA-14-114-02US Government Resource
- http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_adviVendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-892012.pdf
- https://www.exploit-db.com/exploits/44687/
FAQ
What is CVE-2014-2908?
CVE-2014-2908 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-site scripting (XSS) vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices 2.x and 3.x allows remote attackers to inject arbitrary web script or HTML via unspecified ...
How severe is CVE-2014-2908?
CVE-2014-2908 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-2908?
Check the references section above for vendor advisories and patch information. Affected products include: Siemens Simatic S7 Cpu 1200 Firmware, Siemens Simatic S7 Cpu-1211C, Siemens Simatic S7 Cpu 1212C, Siemens Simatic S7 Cpu 1214C, Siemens Simatic S7 Cpu 1215C.