CVE Database
/

CVE-2017-12734

Back to search

CVE-2017-12734

Published: Aug 30, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V1.81.2). An attacker with network access to the integrated web server on port 80/tcp could obtain the session ID of an active user session. A user must be logged in to the web interface. Siemens recommends to use the integrated webserver on port 80/tcp only in trusted networks.

VendorProductVersions

Siemens

LOGO! 8 BM (incl. SIPLUS variants)

affected
All versions < V1.81.2

Weaknesses (CWE)

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now