9.8

CVE-2020-15798

A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V16 Update 3a), SIMATIC HMI KTP Mobile Panels (All versions < V16 Update 3a), SINAMICS GH150 (All versions), SINAMICS GL150 (with option X30) (All versions), SINAMICS GM150 (with option X30) (All versions), SINAMICS SH150 (All versions), SINAMICS SL150 (All versions), SINAMICS SM120 (All versions), SINAMICS SM150 (All versions), SINAMICS SM150i (All versions). Affected devices with enabled telnet service do not require authentication for this service. This could allow a remote attacker to gain full access to the device. (ZDI-CAN-12046)

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SiemensSimatic Hmi Comfort Panels Firmware Version16.0 Updateupdate1
SiemensSimatic Hmi Comfort Panels Firmware Version16.0 Updateupdate2
SiemensSimatic Hmi Comfort Panels Firmware Version16.0 Updateupdate3
SiemensSimatic Hmi Ktp Mobile Panels Firmware Version16.0 Updateupdate1
SiemensSimatic Hmi Ktp Mobile Panels Firmware Version16.0 Updateupdate2
SiemensSimatic Hmi Ktp Mobile Panels Firmware Version16.0 Updateupdate3
SiemensSinamics Gh150 Firmware Version-
   SiemensSinamics Gh150 Version-
SiemensSinamics Gl150 Firmware Version-
   SiemensSinamics Gl150 Version-
SiemensSinamics Gm150 Firmware Version-
   SiemensSinamics Gm150 Version-
SiemensSinamics Sh150 Firmware Version-
   SiemensSinamics Sh150 Version-
SiemensSinamics Sl150 Firmware Version-
   SiemensSinamics Sl150 Version-
SiemensSinamics Sm150 Firmware Version-
   SiemensSinamics Sm150 Version-
SiemensSinamics Sm120 Firmware Version-
   SiemensSinamics Sm120 Version-
SiemensSinamics Sm150i Firmware Version-
   SiemensSinamics Sm150i Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.18% 0.768
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.