A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V16 Update 3a), SIMATIC HMI KTP Mobile Panels (All versions < V16 Update 3a), SINAMICS GH150 (All versions), SINAMICS GL150 (with option X30) (All versions), SINAMICS GM150 (with option X30) (All versions), SINAMICS SH150 (All versions), SINAMICS SL150 (All versions), SINAMICS SM120 (All versions), SINAMICS SM150 (All versions), SINAMICS SM150i (All versions). Affected devices with enabled telnet service do not require authentication for this service. This could allow a remote attacker to gain full access to the device. (ZDI-CAN-12046)
Project Subscriptions
| Vendors | Products |
|---|---|
|
Siemens
Subscribe
|
Simatic Hmi Comfort Panels
Subscribe
Simatic Hmi Comfort Panels Firmware
Subscribe
Simatic Hmi Ktp Mobile Panels
Subscribe
Simatic Hmi Ktp Mobile Panels Firmware
Subscribe
Sinamics Gh150
Subscribe
Sinamics Gh150 Firmware
Subscribe
Sinamics Gl150
Subscribe
Sinamics Gl150 Firmware
Subscribe
Sinamics Gm150
Subscribe
Sinamics Gm150 Firmware
Subscribe
Sinamics Sh150
Subscribe
Sinamics Sh150 Firmware
Subscribe
Sinamics Sl150
Subscribe
Sinamics Sl150 Firmware
Subscribe
Sinamics Sm120
Subscribe
Sinamics Sm120 Firmware
Subscribe
Sinamics Sm150
Subscribe
Sinamics Sm150 Firmware
Subscribe
Sinamics Sm150i
Subscribe
Sinamics Sm150i Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-7781 | A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V16 Update 3a), SIMATIC HMI KTP Mobile Panels (All versions < V16 Update 3a), SINAMICS GH150 (All versions), SINAMICS GL150 (with option X30) (All versions), SINAMICS GM150 (with option X30) (All versions), SINAMICS SH150 (All versions), SINAMICS SL150 (All versions), SINAMICS SM120 (All versions), SINAMICS SM150 (All versions), SINAMICS SM150i (All versions). Affected devices with enabled telnet service do not require authentication for this service. This could allow a remote attacker to gain full access to the device. (ZDI-CAN-12046) |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: siemens
Published:
Updated: 2024-08-04T13:30:21.706Z
Reserved: 2020-07-15T00:00:00
Link: CVE-2020-15798
No data.
Status : Modified
Published: 2021-02-09T17:15:13.437
Modified: 2024-11-21T05:06:12.120
Link: CVE-2020-15798
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD