CVE-2014-2909: Siemens SIMATIC s7 CPU-1211c
Medium severity, CVSS 5.8. EPSS: 2.4% chance of exploitation in the next 30 days.
CRLF injection vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices 2.x and 3.x allows remote attackers to inject arbitrary HTTP headers via unspecified vectors.
Affected products
- Siemens SIMATIC s7 CPU-1211c
- Siemens SIMATIC s7 CPU 1200 Firmware: version 2.0 only; version 3.0 only; version 3.0.2 only
- Siemens SIMATIC s7 CPU 1212c
- Siemens SIMATIC s7 CPU 1214c
- Siemens SIMATIC s7 CPU 1215c
- Siemens SIMATIC s7 CPU 1217c
Published 2014-04-25. Last modified 2026-06-17.