CVE-2018-13800
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability has been identified in SIMATIC S7-1200 CPU family version 4 (All versions < V4.2.3). The web interface could allow a Cross-Site Request Forgery (CSRF) attack if an unsuspecting user is tricked into accessing a malicious link. Successful exploitation requires user interaction by a legitimate user, who must be authenticated to the web interface. A successful attack could allow an attacker to trigger actions via the web interface that the legitimate user is allowed to perform. This could allow the attacker to read or modify parts of the device configuration.
Se ha identificado una vulnerabilidad en la familia de CPU SIMATIC S7-1200 (todas las versiones anteriores a V4.2.3). La interfaz web podría permitir un ataque Cross-Site Request Forgery (CSRF) si un usuario incauto es engañado para que acceda a un enlace malicioso. Su explotación con éxito requiere interacción por parte del usuario legítimo, que debe estar autenticado en la interfaz web. Un ataque exitoso podría permitir que un atacante desencadene acciones en la interfaz web que el usuario legítimo puede realizar. Esto podría permitir que el atacante lea o modifique partes de la configuración del dispositivo.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-07-10 CVE Reserved
- 2018-10-10 CVE Published
- 2024-07-24 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/105542 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-507847.pdf | 2019-10-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Siemens Search vendor "Siemens" | Simatic S7-1200 V4 Firmware Search vendor "Siemens" for product "Simatic S7-1200 V4 Firmware" | < 4.2.3 Search vendor "Siemens" for product "Simatic S7-1200 V4 Firmware" and version " < 4.2.3" | - |
Affected
| in | Siemens Search vendor "Siemens" | Simatic S7-1200 V4 Search vendor "Siemens" for product "Simatic S7-1200 V4" | - | - |
Safe
|