Vulnerabilità · 138 giorni fa

Alcune interfacce web PLC Siemens sono ancora prive di correzioni

Il punto debole qui non è la logica di controllo. È il web server SIMATIC S7, quindi l’esposizione si trova nell’interfaccia di gestione che gli operatori usano per amministrare i PLC, e alcuni modelli interessati non hanno ancora una versione di correzione disponibile.

CVE-2026-25786

NVD KEV

CVSS 9.1 CRITICAL: affected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters… EPSS 0.5% (43º percentile).

CVE-2026-25787

NVD KEV

CVSS 9.1 CRITICAL: affected devices do not properly validate and sanitize Technology Object (TO) name rendered on the "Motion Control Diagnostics" page of the web interface. EPSS 0.5% (43º percentile).

CVE-2026-25789

NVD KEV

CVSS 7.1 HIGH: affected devices do not properly validate and sanitize filenames on the Firmware Update page. EPSS 0.5% (38º percentile).

Cronologia

Fonti

1 fonte che coprono questa storia

Entità

Part of the PlainSec briefing for 2026-05-14

Editions

Storie correlate