{"uid":"cap_tQreDFkmnDBHBhdKm7-9s","slug":"ot-intel-api-onrender-com-10fa9eeb","name":"OT Intel API - SCADA/ICS Internet-Exposed Device Lookup","description":"ICS/OT device exposure lookup. Pass ?vendor=siemens&model=s7-1200. Returns default credential risk, exposed OT protocols (Modbus/502, S7comm/102, DNP3/20000), exploitation notes, and hardening steps. Covers Siemens, Schneider, Rockwell, Honeywell, GE, Unitronics, Beckhoff.","url":"https://ot-intel-api.onrender.com/ot/device","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":["vendor","model"],"properties":{"model":{"type":"string","description":"Model or product line e.g. s7-1200, quantum, logix, vision"},"vendor":{"type":"string","description":"Vendor name e.g. siemens, schneider, rockwell, honeywell, unitronics, ge, beckhoff"}}}},"additionalProperties":false},"output":{"type":"object","required":["type"],"properties":{"type":{"type":"string"},"example":{"type":"object"}}}}},"responseSchema":{"type":"json","example":{"query":{"model":"vision","vendor":"unitronics"},"freshness":"2025-05-22T10:00:00.000Z","data_sources":["NVD","CISA-ICS-CERT","DeepSeek-CTI-Analysis"],"recommended_action":"Change default credentials immediately. No downtime required.","ot_protocols_at_risk":["PCOM (20256)","Modbus TCP (502)"],"default_credential_risk":{"note":"Default password 1111 on port 20256. Actively exploited by IRGC 2023–2024.","risk":"critical"}}},"example":{"request":{"input":{"type":"http","method":"GET","queryParams":{"model":"S7-1200","vendor":"Siemens"}}},"response":{"_type":"device","query":{"model":"S7-1200","vendor":"Siemens"},"freshness":"2026-05-29T04:43:29.161Z","recent_cves":[{"cve_id":"CVE-2012-3037","summary":"The Siemens SIMATIC S7-1200 2.x PLC does not properly protect the private key of the SIMATIC CONTROLLER Certification Authority certificate, which allows remote attackers to spoof the S7-1200 web serv","severity":"MEDIUM","cvss_score":4.3},{"cve_id":"CVE-2012-3040","summary":"Cross-site scripting (XSS) vulnerability in the web server on Siemens SIMATIC S7-1200 PLCs 2.x through 3.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URI.","severity":"MEDIUM","cvss_score":4.3},{"cve_id":"CVE-2013-0700","summary":"Siemens SIMATIC S7-1200 PLCs 2.x and 3.x allow remote attackers to cause a denial of service (defect-mode transition and control outage) via crafted packets to TCP port 102 (aka the ISO-TSAP port).","severity":"HIGH","cvss_score":7.8},{"cve_id":"CVE-2013-2780","summary":"Siemens SIMATIC S7-1200 PLCs 2.x and 3.x allow remote attackers to cause a denial of service (defect-mode transition and control outage) via crafted packets to UDP port 161 (aka the SNMP port).","severity":"HIGH","cvss_score":7.8},{"cve_id":"CVE-2014-2249","summary":"Cross-site request forgery (CSRF) vulnerability on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 and SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allows remote attacke","severity":"MEDIUM","cvss_score":5.8},{"cve_id":"CVE-2014-2250","summary":"The random-number generator on Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 does not have sufficient entropy, which makes it easier for remote attackers to defeat cryptographic pro","severity":"HIGH","cvss_score":8.3},{"cve_id":"CVE-2014-2252","summary":"Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted PROFINET packets, a different vulnerability th","severity":"MEDIUM","cvss_score":6.1},{"cve_id":"CVE-2014-2254","summary":"Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted HTTP packets, a different vulnerability than C","severity":"HIGH","cvss_score":7.8},{"cve_id":"CVE-2014-2256","summary":"Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted ISO-TSAP packets, a different vulnerability th","severity":"HIGH","cvss_score":7.8},{"cve_id":"CVE-2014-2258","summary":"Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allow remote attackers to cause a denial of service (defect-mode transition) via crafted HTTPS packets, a different vulnerability than ","severity":"HIGH","cvss_score":7.8}],"data_sources":["NVD","CISA-ICS-CERT","DeepSeek-CTI-Analysis"],"cisa_advisories":[{"id":"ICSA-26-139-02","url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-139-02","title":"Siemens RUGGEDCOM APE1808 Devices","cvss_max":null,"severity":"low"},{"id":"ICSA-26-134-03","url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-03","title":"Siemens Solid Edge","cvss_max":null,"severity":"low"},{"id":"ICSA-26-134-04","url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-04","title":"Siemens Teamcenter","cvss_max":null,"severity":"low"},{"id":"ICSA-26-134-12","url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-12","title":"Siemens Ruggedcom Rox","cvss_max":null,"severity":"low"},{"id":"ICSA-26-134-02","url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-134-02","title":"Siemens Ruggedcom Rox","cvss_max":null,"severity":"low"}],"hardening_steps":["Update firmware to version 4.0 or later to mitigate multiple CVEs (e.g., CVE-2014-2250, CVE-2014-2254).","Disable unused services such as SNMP, HTTP, and HTTPS if not required for operations.","Change default credentials immediately and enforce strong password policies.","Restrict network access to the PLC using firewalls and VLAN segmentation, allowing only trusted IPs on ports 102 and 161.","Enable secure communication (e.g., HTTPS with valid certificates) and disable legacy protocols like ISO-TSAP if possible."],"recommended_action":"Update firmware to version 4.0 or later and change default credentials immediately to address critical vulnerabilities and reduce attack surface.","ot_protocols_at_risk":["ISO-TSAP (TCP 102)","PROFINET (DCP, PTCP)","SNMP (UDP 161)","HTTP/HTTPS (TCP 80/443)"],"internet_exposure_risk":"HIGH — S7-1200 devices are frequently exposed on Shodan via open ports 102 (ISO-TSAP) and 80/443 (web server), making them targets for remote exploitation.","default_credential_risk":{"note":"Siemens S7-1200 PLCs have been found with default credentials (e.g., 'admin'/'admin') in older firmware versions, and the device does not enforce password change on first login, increasing risk of unauthorized access.","risk":"high"},"known_default_credentials":{"exists":true,"details":"Default credentials for Siemens S7-1200 are often 'admin'/'admin' for the web interface and 'Siemens'/'Siemens' for the TIA Portal access; these are widely documented in security advisories and should be changed."}}},"exampleRequest":{"model":"S7-1200","vendor":"Siemens"},"tags":["x402"],"displayCostAmount":"0.05","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"settled","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.05/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.05","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_hxarSV0eX5hgkvJUZdynz","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.05","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Looks up internet-exposed industrial control system devices by vendor and model, returning default credential risks, at-risk OT protocols, exploitation notes, and hardening recommendations.","exampleAgentPrompt":"Can you check the internet-exposure risk for a Siemens S7-1200 PLC — I want to know about default credential issues, which OT protocols like Modbus or S7comm are at risk, any known exploitation details, and what hardening steps I should take?","exampleUseCases":[{"title":"Assess exposed Schneider Electric device risks","prompt":"We found a Schneider Electric PLC exposed on the internet. Can you look up what default credentials might be compromised, which industrial protocols are vulnerable on that device, and what hardening actions we should prioritize to secure it?"},{"title":"Evaluate Rockwell Automation controller security posture","prompt":"I need to understand the threat landscape for our Rockwell Automation CompactLogix controllers that are internet-reachable. What are the main exploitation risks, do they have default credential vulnerabilities, and what OT protocols should we lock down?"},{"title":"Triage GE industrial device vulnerability exposure","prompt":"Can you assess a GE Automation device we discovered on the internet for default credential risk and protocol-level exposure? I need to know what's vulnerable—Modbus, DNP3, S7comm—and what specific hardening steps apply to this model."}],"resultDescription":"Returns a structured report including default credential risk level, list of at-risk OT protocols (Modbus/502, DNP3/20000, S7comm/102), exploitation notes specific to the device, and recommended hardening actions for the queried vendor and model combination.","failureModes":["Unknown vendor or model returns no results or 404","Missing required query parameters (vendor or model) returns 400 error","Render.com cold-start latency may cause first request to be slow","Rate limiting or payment failure for x402 micropayment may block access","Device not in database returns empty or partial results"],"whenToPreferThis":"Use this endpoint when you need to assess the security posture of a specific internet-exposed ICS/SCADA device by vendor and model, particularly to understand default credential risks, exposed industrial protocols, and actionable hardening steps. Prefer this over general CVE lookup endpoints when the concern is protocol-level exposure and device-specific hardening for OT environments rather than software vulnerability triage.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-15T06:31:54.848Z","isFirstParty":false}