Executive brief
Siemens SIMATIC S7 PLCs, which are industrial controllers used to automate factory processes and infrastructure, are affected by a security flaw in their built-in web management interface. An attacker could trick an authorized user into selecting a specially crafted file on the firmware update page, causing malicious code to run in the user's browser. This could allow the attacker to steal login credentials or take over the user's active session, potentially gaining unauthorized access to the industrial control system.
Technical details
A Cross-Site Scripting (XSS) vulnerability (CWE-79) exists in the web server component of multiple Siemens SIMATIC S7 PLC families. The vulnerability is located in the Firmware Update page, which fails to properly validate and sanitize filenames before they are processed by the browser. An attacker with low privileges could use social engineering to trick an authenticated administrator into selecting a maliciously named file. The exploit triggers JavaScript execution in the context of the user's session even without the file being fully uploaded. Siemens has released firmware updates for several product lines (e.g., V3.1.6, V2.9.9, V4.1.6) to address this issue, though some legacy models currently have no planned fix.
Affected products
- Siemens SIMATIC Drive Controller CPU 1504D TF < V3.1.6
- Siemens SIMATIC Drive Controller CPU 1507D TF < V3.1.6
- Siemens SIMATIC ET 200SP CPU 1510SP F-1 PN (6ES7510-1SJ01-0AB0) < V2.9.9
- Siemens SIMATIC ET 200SP CPU 1510SP F-1 PN (6ES7510-1SK03-0AB0) < V4.1.6
- Siemens SIMATIC ET 200SP Open Controller CPU 1515SP PC2 All versions
- Siemens SIMATIC S7-1500 CPU 1511-1 PN (6ES7511-1AK01-0AB0) < V2.9.9
Timeline
- 2026-05-12: advisory: Initial publication by Siemens and NVD
- 2026-07-14: other: Advisory updated to version V1.1