CRITICAL · 9.8

CVE-2020-15798

A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V16 Update 3a), SIMATIC HMI KTP Mobile Panels (All versions < V16 Update 3a), SINAMICS GH150 (...

Vulnerability Description

A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V16 Update 3a), SIMATIC HMI KTP Mobile Panels (All versions < V16 Update 3a), SINAMICS GH150 (All versions), SINAMICS GL150 (with option X30) (All versions), SINAMICS GM150 (with option X30) (All versions), SINAMICS SH150 (All versions), SINAMICS SL150 (All versions), SINAMICS SM120 (All versions), SINAMICS SM150 (All versions), SINAMICS SM150i (All versions). Affected devices with enabled telnet service do not require authentication for this service. This could allow a remote attacker to gain full access to the device. (ZDI-CAN-12046)

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
SiemensSimatic Hmi Comfort Panels Firmware< 16.0
SiemensSimatic Hmi Comfort Panels-
SiemensSimatic Hmi Ktp Mobile Panels Firmware< 16.0
SiemensSimatic Hmi Ktp Mobile Panels-
SiemensSinamics Gh150 Firmware-
SiemensSinamics Gh150-
SiemensSinamics Gl150 Firmware-
SiemensSinamics Gl150-
SiemensSinamics Gm150 Firmware-
SiemensSinamics Gm150-
SiemensSinamics Sh150 Firmware-
SiemensSinamics Sh150-
SiemensSinamics Sl150 Firmware-
SiemensSinamics Sl150-
SiemensSinamics Sm150 Firmware-
SiemensSinamics Sm150-
SiemensSinamics Sm120 Firmware-
SiemensSinamics Sm120-
SiemensSinamics Sm150I Firmware-
SiemensSinamics Sm150I-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-15798?

CVE-2020-15798 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V16 Update 3a), SIMATIC HMI KTP Mobile Panels (All versions < V16 Update 3a), SINAMICS GH150 (...

How severe is CVE-2020-15798?

CVE-2020-15798 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2020-15798?

Check the references section above for vendor advisories and patch information. Affected products include: Siemens Simatic Hmi Comfort Panels Firmware, Siemens Simatic Hmi Comfort Panels, Siemens Simatic Hmi Ktp Mobile Panels Firmware, Siemens Simatic Hmi Ktp Mobile Panels, Siemens Sinamics Gh150 Firmware.