The random-number generator on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 does not have sufficient entropy, which makes it easier for remote attackers to defeat cryptographic protection mechanisms and hijack sessions via unspecified vectors.
2014-03-16T14:06:45.867
2025-04-12T10:46:40.837
Deferred
CVSSv2: 8.3 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:C
8.6
8.5
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | siemens | simatic_s7-1500_cpu_firmware | ≤ 1.1.2 | Yes |
Operating System | siemens | simatic_s7-1500_cpu_firmware | 1.0.1 | Yes |
Operating System | siemens | simatic_s7-1500_cpu_firmware | 1.1.0 | Yes |
Operating System | siemens | simatic_s7-1500_cpu_firmware | 1.1.1 | Yes |