The vendor explicitly identifies these products as affected by this CVE.
- SIMATIC Drive Controller CPU 1504D TF (6ES7615-4DF10-0AB0)
- SIMATIC Drive Controller CPU 1507D TF (6ES7615-7DF10-0AB0)
- SIMATIC ET 200pro IM154-8 PN/DP CPU (6ES7154-8AB01-0AB0)
- SIMATIC ET 200pro IM154-8F PN/DP CPU (6ES7154-8FB01-0AB0)
- SIMATIC ET 200pro IM154-8FX PN/DP CPU (6ES7154-8FX00-0AB0)
- SIMATIC ET 200S IM151-8 PN/DP CPU (6ES7151-8AB01-0AB0)
- SIMATIC ET 200S IM151-8F PN/DP CPU (6ES7151-8FB01-0AB0)
- SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants)
- SIMATIC PC Station
- SIMATIC S7-1200 CPU family (incl. SIPLUS variants)
- SIMATIC S7-1500 CPU 1510SP F-1 PN (6ES7510-1SJ00-0AB0)
- SIMATIC S7-1500 CPU 1510SP F-1 PN (6ES7510-1SJ01-0AB0)
- Summary
- The login endpoint /FormLogin in affected web services does not apply proper origin checking. This could allow authenticated remote attackers to track the activities of other users via a login cross-site request forgery attack.
- Remediation
- Update to V17 Update 5 or later version
