Skip to content

CVE-2014-2909

CRLF injection vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices 2.x and 3.x allows remote attackers to inject arbitrary HTTP headers via unspecified vectors.

View on NVD

Severity

N/A

EPSS

Probability of exploitation (next 30 days): 0.0084 (0.8%)
Percentile: 74.8%
EPSS: 2026-05-06

Affects

siemens:simatic_s7_cpu_1200_firmwaresiemens:simatic_s7_cpu-1211csiemens:simatic_s7_cpu_1212csiemens:simatic_s7_cpu_1214csiemens:simatic_s7_cpu_1215csiemens:simatic_s7_cpu_1217c

Technical description

CRLF injection vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices 2.x and 3.x allows remote attackers to inject arbitrary HTTP headers via unspecified vectors.

Published: 4/25/2014, 5:12:07 AM
Last modified: 5/6/2026, 10:30:45 PM

References

HomeEventsBlogResourcesTeam