VendorsSiemenssimatic_s7-1200_cpu_1215_fc_firmwareall versions
Vulnerabilities

Siemens SIMATIC S7-1200 CPU 1215 FC Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2013-0700
Siemens SIMATIC S7-1200 PLCs 2.x and 3.x allow remote attackers to cause a denial of service (defect-mode transition and control outage) via crafted packets to TCP port 102 (aka the ISO-TSAP port).
Published 2013-04-22 · Modified
7.8EPSS 0.024
CVE-2013-2780
Siemens SIMATIC S7-1200 PLCs 2.x and 3.x allow remote attackers to cause a denial of service (defect-mode transition and control outage) via crafted packets to UDP port 161 (aka the SNMP port).
Published 2013-04-22 · Modified
7.8EPSS 0.024
CVE-2021-40365
Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.
Published 2022-12-13 · Modified
7.5EPSS 0.009
CVE-2021-44693
Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.
Published 2022-12-13 · Modified
7.5EPSS 0.007
CVE-2021-44695
Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.
Published 2022-12-13 · Modified
7.5EPSS 0.007
CVE-2021-44694
Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.
Published 2022-12-13 · Modified
7.5EPSS 0.006
CVE-2022-30694
The login endpoint /FormLogin in affected web services does not apply proper origin checking. This could allow authenticated remote attackers to track the activities of other users via a login cross-site request forgery attack.
Published 2022-11-08 · Modified
6.5EPSS 0.003
CVE-2021-3449
NULL pointer deref in signature_algorithms processing
Published 2021-03-25 · Modified
5.9EPSS 0.635
CVE-2012-3040
Cross-site scripting (XSS) vulnerability in the web server on Siemens SIMATIC S7-1200 PLCs 2.x through 3.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URI.
Published 2012-10-10 · Modified
4.3EPSS 0.026
CVE-2012-3037
The Siemens SIMATIC S7-1200 2.x PLC does not properly protect the private key of the SIMATIC CONTROLLER Certification Authority certificate, which allows remote attackers to spoof the S7-1200 web server by using this key to create a forged certificate.
Published 2012-09-25 · Modified
4.3EPSS 0.015