CVE-2012-3040
Published Oct 10, 2012
Last updated 3 years ago
Overview
- Description
- Cross-site scripting (XSS) vulnerability in the web server on Siemens SIMATIC S7-1200 PLCs 2.x through 3.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URI.
- Source
- ics-cert@hq.dhs.gov
- NVD status
- Analyzed
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-79
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:simatic_s7-1200_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1D6784CC-7FD8-4CD5-979F-0B9F62CE4AA3", "versionEndExcluding": "3.0.2", "versionStartIncluding": "2.0.0" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:simatic_s7-1200:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "EC545350-FD53-4B2E-886F-E20F12260C9B" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:simatic_s7-1200_cpu_1211c_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "90523ED2-CE36-4287-9D80-4A508DBD6E17", "versionEndExcluding": "3.0.2", "versionStartIncluding": "2.0.0" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:simatic_s7-1200_cpu_1211c:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "3871C0C9-C65E-4E0B-9CA8-75E60066297F" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:simatic_s7-1200_cpu_1212c_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0D31C744-AD8E-4E72-9E3E-F9ED8EFE2D8A", "versionEndExcluding": "3.0.2", "versionStartIncluding": "2.0.0" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:simatic_s7-1200_cpu_1212c:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "07849777-92E7-41D2-9128-F8D20DE15391" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:simatic_s7-1200_cpu_1212fc_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E7EF332E-0725-44BB-8233-66B017D9DB20", "versionEndExcluding": "3.0.2", "versionStartIncluding": "2.0.0" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:simatic_s7-1200_cpu_1212fc:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "68B3573B-A31E-4489-B2DD-B01B5C1D03CB" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:simatic_s7-1200_cpu_1214_fc_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "30F62D4A-8014-4B82-B219-37385F902436", "versionEndExcluding": "3.0.2", "versionStartIncluding": "2.0.0" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:simatic_s7-1200_cpu_1214_fc:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "B640800C-9263-4BEA-9DA5-1323932540BD" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:simatic_s7-1200_cpu_1214c_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "021DC100-8C4D-452B-93E1-952AD9DA0954", "versionEndExcluding": "3.0.2", "versionStartIncluding": "2.0.0" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:simatic_s7-1200_cpu_1214c:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "FE17584A-BF7A-48B8-A9CB-477663766C63" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:simatic_s7-1200_cpu_1215_fc_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F6058C37-D10F-498B-80A6-E6608BCAF793", "versionEndExcluding": "3.0.2", "versionStartIncluding": "2.0.0" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:simatic_s7-1200_cpu_1215_fc:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "76C7D55C-8D99-4E2F-A254-1BDE2B12A203" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:simatic_s7-1200_cpu_1215c_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8339C357-7788-4D44-9075-CA3FFB837453", "versionEndExcluding": "3.0.2", "versionStartIncluding": "2.0.0" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:simatic_s7-1200_cpu_1215c:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "CC4698CF-F935-4707-BA91-7E3650C7956C" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:simatic_s7-1200_cpu_1217c_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2D1B4F7D-D7A6-4E79-9EE1-211394B37AA7", "versionEndExcluding": "3.0.2", "versionStartIncluding": "2.0.0" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:simatic_s7-1200_cpu_1217c:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "232279DE-CF1C-4A3C-886D-B4CE3F104F09" } ], "operator": "OR" } ], "operator": "AND" } ]