CRITICAL · 9.8

CVE-2020-15786

A vulnerability has been identified in SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants) (All versions < V16), SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions <= V16), S...

Vulnerability Description

A vulnerability has been identified in SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants) (All versions < V16), SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions <= V16), SIMATIC HMI Mobile Panels (All versions <= V16), SIMATIC HMI Unified Comfort Panels (All versions <= V16). Affected devices insufficiently block excessive authentication attempts. This could allow a remote attacker to discover user passwords and obtain access to the Sm@rt Server via a brute-force attack.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
SiemensSimatic Hmi Basic Panels 2Nd Generation Firmware<= 14
SiemensSimatic Hmi Basic Panels 2Nd Generation-
SiemensSimatic Hmi Comfort Panels FirmwareAll versions
SiemensSimatic Hmi Comfort Panels-
SiemensSimatic Hmi Mobile Panels FirmwareAll versions
SiemensSimatic Hmi Mobile Panels-
SiemensSimatic Hmi United Comfort Panels FirmwareAll versions
SiemensSimatic Hmi United Comfort Panels-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-15786?

CVE-2020-15786 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A vulnerability has been identified in SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants) (All versions < V16), SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions <= V16), S...

How severe is CVE-2020-15786?

CVE-2020-15786 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2020-15786?

Check the references section above for vendor advisories and patch information. Affected products include: Siemens Simatic Hmi Basic Panels 2Nd Generation Firmware, Siemens Simatic Hmi Basic Panels 2Nd Generation, Siemens Simatic Hmi Comfort Panels Firmware, Siemens Simatic Hmi Comfort Panels, Siemens Simatic Hmi Mobile Panels Firmware.