CVE-2011-20001 Details
Description
A vulnerability has been identified in SIMATIC S7-1200 CPU V1 family (incl. SIPLUS variants) (All versions < V2.0.3), SIMATIC S7-1200 CPU V2 family (incl. SIPLUS variants) (All versions < V2.0.3). The web server interface of affected devices improperly processes incoming malformed HTTP traffic at high rate. This could allow an unauthenticated remote attacker to force the device entering the stop/defect state, thus creating a denial of service condition.
A denial-of-service vulnerability has been identified in Siemens SIMATIC S7-1200 CPU V1 and V2 families, including SIPLUS variants, all versions prior to V2.0.3. The issue arises because the web server interface improperly handles incoming malformed HTTP traffic at a high rate. This flaw could enable an unauthenticated remote attacker to force the device into a stop or defect state, creating a denial-of-service condition.
Siemens recommends updating to the latest version. If an update is not possible, the web server can be disabled, if feasible.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 14, 2025CISA-ADP
Assessed Oct 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-625789.html | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Siemens SIMATIC S7-1200 CPU V1 | < V2.0.3 |
CPE
Remediation
| |
| Siemens SIMATIC S7-1200 CPU V2 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 16, 2026 | CVE Modified | [email protected] |
| Jun 16, 2026 | CVE Modified | CISA-ADP |
| Oct 14, 2025 | New CVE Received | [email protected] |
Volerion