Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 21 Oct 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Siemens
Siemens simatic Siemens simatic S7-1200 Siemens simatic S7-1200 Cpu |
|
| Vendors & Products |
Siemens
Siemens simatic Siemens simatic S7-1200 Siemens simatic S7-1200 Cpu |
Tue, 14 Oct 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Oct 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified in SIMATIC S7-1200 CPU V1 family (incl. SIPLUS variants) (All versions < V2.0.2), SIMATIC S7-1200 CPU V2 family (incl. SIPLUS variants) (All versions < V2.0.2). Affected controllers are vulnerable to capture-replay in the communication with the engineering software. This could allow an on-path attacker between the engineering software and the controller to execute any previously recorded commands at a later time (e.g. set the controller to STOP), regardless whether or not the controller had a password configured. | |
| Weaknesses | CWE-294 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: siemens
Published:
Updated: 2025-10-14T18:58:30.327Z
Reserved: 2025-05-22T04:58:58.076Z
Link: CVE-2011-20002
Updated: 2025-10-14T18:58:27.226Z
Status : Deferred
Published: 2025-10-14T10:15:33.633
Modified: 2026-04-15T00:35:42.020
Link: CVE-2011-20002
No data.
OpenCVE Enrichment
Updated: 2025-10-21T09:42:54Z