Executive brief
Siemens SIMATIC S7-1500 and related industrial controllers contain a security vulnerability in their built-in web management interface. An attacker with the ability to download projects to the controller can inject malicious code that executes when an administrator views the diagnostics page. This could lead to the theft of administrative session credentials or unauthorized control over the device's web-based management functions.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in the web server of multiple Siemens SIMATIC S7 PLC families, including S7-1500 and ET 200SP. The vulnerability is caused by improper validation and sanitization of Technology Object (TO) names rendered on the 'Motion Control Diagnostics' page. An authenticated attacker with privileges to download a TIA project to the PLC can use a specially crafted TO name to inject malicious scripts. When a legitimate user with appropriate rights accesses the affected diagnostics page, the script executes within their browser session. This can result in a full compromise of the user's web session, potentially allowing the attacker to perform administrative actions or escalate privileges. Siemens has released firmware updates for several product lines to address this issue.
Affected products
- Siemens SIMATIC S7-1500 CPU family All versions < V2.9.9 or < V4.1.6 (depending on model)
- Siemens SIMATIC Drive Controller family All versions < V3.1.6
- Siemens SIMATIC ET 200SP CPU family All versions < V2.9.9 or < V4.1.6 (depending on model)
- Siemens SIMATIC ET 200SP Open Controller All versions
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory
- 2026-07-14: other: Advisory updated by Siemens