Siemens S7-1200 4.5 Unauthenticated Access
On March 10, 2022, a researcher dubbed "RoseSecurity", published an exploit on PacketStorm, titled "Siemens S7-1200 4.5 Unauthenticated Access". The exploit is demonstrated by curl commands that show how CPU start/stop commands can be triggered on Siemens S7-1200 devices without prior authentication.
Siemens analyzed this claim. Based on our current knowledge, this exploit would only work if the PLC is misconfigured to "allow Everybody to change operating mode (Start/Stop)" in the webserver user management:
Web Server -> User Management -> Everybody -> Change Operating Mode (Webserver access rights)
In the default configuration this setting is not enabled. When properly configured, the PLC does not allow to change operating mode via unauthenticated POST requests.
Siemens has created a Product Support article to provide further information how to securely configure access to the Web server and related APIs.