Vulnerability Details CVE-2012-3037
The Siemens SIMATIC S7-1200 2.x PLC does not properly protect the private key of the SIMATIC CONTROLLER Certification Authority certificate, which allows remote attackers to spoof the S7-1200 web server by using this key to create a forged certificate.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 69.4%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2012-3037
-
cpe:2.3:h:siemens:simatic_s7-1200:-
-
cpe:2.3:h:siemens:simatic_s7-1200_cpu_1211c:-
-
cpe:2.3:h:siemens:simatic_s7-1200_cpu_1212c:-
-
cpe:2.3:h:siemens:simatic_s7-1200_cpu_1212fc:-
-
cpe:2.3:h:siemens:simatic_s7-1200_cpu_1214_fc:-
-
cpe:2.3:h:siemens:simatic_s7-1200_cpu_1214c:-
-
cpe:2.3:h:siemens:simatic_s7-1200_cpu_1215_fc:-
-
cpe:2.3:h:siemens:simatic_s7-1200_cpu_1215c:-
-
cpe:2.3:h:siemens:simatic_s7-1200_cpu_1217c:-
-
cpe:2.3:o:siemens:simatic_s7-1200_cpu_1211c_firmware:*
-
cpe:2.3:o:siemens:simatic_s7-1200_cpu_1212c_firmware:*
-
cpe:2.3:o:siemens:simatic_s7-1200_cpu_1212fc_firmware:*
-
cpe:2.3:o:siemens:simatic_s7-1200_cpu_1214_fc_firmware:*
-
cpe:2.3:o:siemens:simatic_s7-1200_cpu_1214c_firmware:*
-
cpe:2.3:o:siemens:simatic_s7-1200_cpu_1215_fc_firmware:*
-
cpe:2.3:o:siemens:simatic_s7-1200_cpu_1215c_firmware:*
-
cpe:2.3:o:siemens:simatic_s7-1200_cpu_1217c_firmware:*
-
cpe:2.3:o:siemens:simatic_s7-1200_firmware:*