CVE-2026-25786
CVSS 9.1 CRITICAL: affected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters… EPSS 0.5% (43º percentile).
Vulnerabilità · 138 giorni fa
Il punto debole qui non è la logica di controllo. È il web server SIMATIC S7, quindi l’esposizione si trova nell’interfaccia di gestione che gli operatori usano per amministrare i PLC, e alcuni modelli interessati non hanno ancora una versione di correzione disponibile.
CVSS 9.1 CRITICAL: affected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters… EPSS 0.5% (43º percentile).
CVSS 9.1 CRITICAL: affected devices do not properly validate and sanitize Technology Object (TO) name rendered on the "Motion Control Diagnostics" page of the web interface. EPSS 0.5% (43º percentile).
CVSS 7.1 HIGH: affected devices do not properly validate and sanitize filenames on the Firmware Update page. EPSS 0.5% (38º percentile).
1 fonte che coprono questa storia
Siemens SIMATIC S7 PLC Web Server | CISA
Siemens SIMATIC S7 PLC Web Server Summary SIMATIC S7 PLCs contain multiple vulnerabilities in the web server that could allow an attacker to perform cross-site scripting attacks.
Part of the PlainSec briefing for 2026-05-14