The vendor explicitly identifies these products as affected by this CVE.
- SIMATIC Drive Controller CPU 1504D TF (6ES7615-4DF10-0AB0) < V3.1.6
- SIMATIC Drive Controller CPU 1507D TF (6ES7615-7DF10-0AB0) < V3.1.6
- SIMATIC ET 200SP CPU 1510SP F-1 PN (6ES7510-1SJ00-0AB0)
- SIMATIC ET 200SP CPU 1510SP F-1 PN (6ES7510-1SJ01-0AB0) < V2.9.9
- SIMATIC ET 200SP CPU 1510SP F-1 PN (6ES7510-1SK03-0AB0) < V4.1.6
- SIMATIC ET 200SP CPU 1510SP-1 PN (6ES7510-1DJ00-0AB0)
- SIMATIC ET 200SP CPU 1510SP-1 PN (6ES7510-1DJ01-0AB0) < V2.9.9
- SIMATIC ET 200SP CPU 1510SP-1 PN (6ES7510-1DK03-0AB0) < V4.1.6
- SIMATIC ET 200SP CPU 1512SP F-1 PN (6ES7512-1SK00-0AB0)
- SIMATIC ET 200SP CPU 1512SP F-1 PN (6ES7512-1SK01-0AB0) < V2.9.9
- SIMATIC ET 200SP CPU 1512SP F-1 PN (6ES7512-1SM03-0AB0) < V4.1.6
- SIMATIC ET 200SP CPU 1512SP-1 PN (6ES7512-1DK00-0AB0)
- Summary
- Affected devices do not properly validate and sanitize PLC/station name rendered on the "communication" parameters page of the web interface. This could allow an authenticated attacker who is authorized to download a TIA project into the product, to inject malicious scripts into the page. If a benign user with appropriate rights accesses the "communication" parameters page, the malicious code would be executed in the scope of their web session.
- Remediation
- Update to V2.9.9 or later version
