Back to search
CVE-2017-12734
Published: Aug 30, 2017
Modified: Aug 5, 2024
PUBLISHED
Description
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V1.81.2). An attacker with network access to the integrated web server on port 80/tcp could obtain the session ID of an active user session. A user must be logged in to the web interface. Siemens recommends to use the integrated webserver on port 80/tcp only in trusted networks.
| Vendor | Product | Versions |
|---|---|---|
Siemens | LOGO! 8 BM (incl. SIPLUS variants) | affected All versions < V1.81.2 |
Weaknesses (CWE)
References
100560
vdb-entry
x_refsource_BID
https://cert-portal.siemens.com/productcert/pdf/ssa-087240.pdf
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now