Vulnerabilità · 204 giorni fa

Falla di code injection nei controller SIMATIC S7-1500

Una vulnerabilità nell'interfaccia web dei controller SIMATIC S7-1500 permette code injection se un utente importa un trace file appositamente creato (CVE-2025-40943). Siemens ha rilasciato patch per diversi modelli e prevede ulteriori fix.

CVE-2025-40943

NVD KEV

CVSS 9.6 CRITICAL: affected devices do not properly sanitize contents of trace files. EPSS 0.5% (36º percentile).

Cronologia

Fonti

1 fonte che coprono questa storia

Entità

Part of the PlainSec briefing for 2026-03-13

Editions

Storie correlate