{ "schema_version": "1.4.0", "id": "GHSA-cq39-26j4-6jcj", "modified": "2022-05-13T01:04:09Z", "published": "2022-05-13T01:04:09Z", "aliases": [ "CVE-2012-3037" ], "details": "The Siemens SIMATIC S7-1200 2.x PLC does not properly protect the private key of the SIMATIC CONTROLLER Certification Authority certificate, which allows remote attackers to spoof the S7-1200 web server by using this key to create a forged certificate.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2012-3037" }, { "type": "WEB", "url": "http://en.securitylab.ru/lab/PT-2012-48" }, { "type": "WEB", "url": "http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-240718.pdf" }, { "type": "WEB", "url": "http://www.us-cert.gov/control_systems/pdf/ICSA-12-263-01.pdf" } ], "database_specific": { "cwe_ids": [ "CWE-295" ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2012-09-25T11:07:00Z" } }