Vulnerabilità ed exploit · Attacco ad app web

Alcune interfacce web PLC Siemens sono ancora prive di correzioni

Il punto debole qui non è la logica di controllo. È il web server SIMATIC S7, quindi l’esposizione si trova nell’interfaccia di gestione che gli operatori usano per amministrare i PLC, e alcuni modelli interessati non hanno ancora una versione di correzione disponibile.

1 fonte · 14 mag

CVE-2026-25786

NVD KEV

CVSS 9.1 CRITICAL: affected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters… EPSS 0.5% (43º percentile).

CVE-2026-25787

NVD KEV

CVSS 9.1 CRITICAL: affected devices do not properly validate and sanitize Technology Object (TO) name rendered on the "Motion Control Diagnostics" page of the web interface. EPSS 0.5% (43º percentile).

CVE-2026-25789

NVD KEV

CVSS 7.1 HIGH: affected devices do not properly validate and sanitize filenames on the Firmware Update page. EPSS 0.5% (38º percentile).

Cronologia

Fonti

Part of the PlainSec briefing for 2026-05-14

Every edition of this story: Alcune interfacce web PLC Siemens sono ancora prive di correzioni

Altro da oggi