CRITICAL · 9.8

CVE-2020-15782

A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) (All versions), SIMATIC ET 200SP ...

Vulnerability Description

A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V21.9), SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (All versions < V4.5.0), SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions < V2.9.2), SIMATIC S7-1500 Software Controller (All versions < V21.9), SIMATIC S7-PLCSIM Advanced (All versions < V4.0), SINAMICS PERFECT HARMONY GH180 Drives (Drives manufactured before 2021-08-13), SINUMERIK MC (All versions < V6.15), SINUMERIK ONE (All versions < V6.15). Affected devices are vulnerable to a memory protection bypass through a specific operation. A remote unauthenticated attacker with network access to port 102/tcp could potentially write arbitrary data and code to protected memory areas or read sensitive data to launch further attacks.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
SiemensSimatic Driver Controller Firmware< 2.9.2
SiemensCpu 1504D Tf-
SiemensCpu 1507D Tf-
SiemensS7-1200 Cpu Firmware< 4.5.0
SiemensCpu 1211C-
SiemensCpu 1212C-
SiemensCpu 1212Fc-
SiemensCpu 1214C-
SiemensCpu 1214Fc-
SiemensCpu 1215C-
SiemensCpu 1215Fc-
SiemensCpu 1217C-
SiemensS7-1500 Cpu Firmware< 2.9.2
Siemens6Es7510-1Dj01-0Ab0-
Siemens6Es7510-1Sj01-0Ab0-
Siemens6Es7511-1Ak01-0Ab0-
Siemens6Es7511-1Ak02-0Ab0-
Siemens6Es7511-1Ck00-0Ab0-
Siemens6Es7511-1Ck01-0Ab0-
Siemens6Es7511-1Fk01-0Ab0-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-15782?

CVE-2020-15782 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC (incl. SIPLUS variants) (All versions), SIMATIC ET 200SP ...

How severe is CVE-2020-15782?

CVE-2020-15782 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2020-15782?

Check the references section above for vendor advisories and patch information. Affected products include: Siemens Simatic Driver Controller Firmware, Siemens Cpu 1504D Tf, Siemens Cpu 1507D Tf, Siemens S7-1200 Cpu Firmware, Siemens Cpu 1211C.