Siemens SENTRON 7KT PAC1261 Data Manager
A vulnerability has been identified in the Siemens SENTRON 7KT PAC1261 Data Manager software, specifically within the Go Project’s net/http package. This allows an attacker to potentially gain administrative control over the device by exploiting a request smuggling flaw. Siemens has released version 2.1.0 to address this issue, and CISA recommends immediate updates to mitigate the risk.
The vulnerability stems from the way the SENTRON 7KT PAC1261 Data Manager handles chunked data, accepting bare LF line terminators incorrectly. This enables an attacker to inject malicious HTTP requests, effectively smuggling them through the server. This could lead to unauthorized access and control over the device. The vulnerability is classified as CWE-444, ‘Inconsistent Interpretation of HTTP Requests’ (HTTP Request/Response Smuggling). Siemens ProductCERT reported the vulnerability to CISA, and the vendor has provided a fix in version 2.1.0. CISA recommends implementing security measures such as encrypted protocols and network segmentation to minimize the potential impact of this exploit.