5.3

CVE-2020-28397

A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V21.9), SIMATIC S7 PLCSIM Advanced (All versions > V2 < V4), SIMATIC S7-1200 CPU family (incl. SIPLUS variants) (Version V4.4), SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions > V2.5 < V2.9.2), SIMATIC S7-1500 Software Controller (All versions > V2.5 < V21.9), TIM 1531 IRC (incl. SIPLUS NET variants) (Version V2.1). Due to an incorrect authorization check in the affected component, an attacker could extract information about access protected PLC program variables over port 102/tcp from an affected device when reading multiple attributes at once.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SiemensCpu 1504d Tf Firmware Version < 2.9.2
   SiemensCpu 1504d Tf Version-
SiemensCpu 1507d Tf Firmware Version < 2.9.2
   SiemensCpu 1507d Tf Version-
SiemensCpu 1515sp Pc2 Tf Firmware Version < 21.9
   SiemensCpu 1515sp Pc2 Tf Version-
SiemensSimatic S7-1500 Software Controller Version >= 2.5 < 21.9
SiemensTim 1531 Irc Firmware Version2.1
   SiemensTim 1531 Irc Version-
SiemensCpu 1211c Firmware Version4.4
   SiemensCpu 1211c Version-
SiemensCpu 1212c Firmware Version4.4
   SiemensCpu 1212c Version-
SiemensCpu 1212fc Firmware Version4.4
   SiemensCpu 1212fc Version-
SiemensCpu 1214fc Firmware Version4.4
   SiemensCpu 1214fc Version-
SiemensCpu 1214c Firmware Version4.4
   SiemensCpu 1214c Version-
SiemensCpu 1215fc Firmware Version4.4
   SiemensCpu 1215fc Version-
SiemensCpu 1215c Firmware Version4.4
   SiemensCpu 1215c Version-
SiemensCpu 1217c Firmware Version4.4
   SiemensCpu 1217c Version-
SiemensSiplus Cpu 1510sp F-1pn Firmware Version >= 2.5 < 2.9.2
   SiemensSiplus Cpu 1510sp F-1pn Version-
SiemensSiplus Cpu 1511-1 Pn Firmware Version >= 2.5 < 2.9.2
   SiemensSiplus Cpu 1511-1 Pn Version-
SiemensSiplus Cpu 1511-1 Pn Firmware Version >= 2.5 < 2.9.2
   SiemensSiplus Cpu 1511-1 Pn Version-
SiemensSiplus Cpu 1511f-1 Pn Firmware Version >= 2.5 < 2.9.2
   SiemensSiplus Cpu 1511f-1 Pn Version-
SiemensSiplus Cpu 1512sp-1 Pn Firmware Version >= 2.5 < 2.9.2
   SiemensSiplus Cpu 1512sp-1 Pn Version-
SiemensSiplus Cpu 1512sp F-1pn Firmware Version >= 2.5 < 2.9.2
   SiemensSiplus Cpu 1512sp F-1pn Version-
SiemensSiplus Cpu 1513-1 Pn Firmware Version >= 2.5 < 2.9.2
   SiemensSiplus Cpu 1513-1 Pn Version-
SiemensSiplus Cpu 1513-1 Pn Firmware Version >= 2.5 < 2.9.2
   SiemensSiplus Cpu 1513-1 Pn Version-
SiemensSiplus Cpu 1513f-1 Pn Firmware Version >= 2.5 < 2.9.2
   SiemensSiplus Cpu 1513f-1 Pn Version-
SiemensSiplus Cpu 1516-3 Pn/dp Firmware Version >= 2.5 < 2.9.2
   SiemensSiplus Cpu 1516-3 Pn/dp Version-
SiemensSiplus Cpu 1516-3 Pn/dp Firmware Version >= 2.5 < 2.9.2
   SiemensSiplus Cpu 1516-3 Pn/dp Version-
SiemensSiplus Cpu-1516f-3 Pn/dp Firmware Version >= 2.5 < 2.9.2
   SiemensSiplus Cpu-1516f-3 Pn/dp Version-
SiemensSiplus Cpu 1518-4 Pn/dp Firmware Version >= 2.5 < 2.9.2
   SiemensSiplus Cpu 1518-4 Pn/dp Version-
SiemensSiplus Cpu 1518f-4 Pn/dp Firmware Version >= 2.5 < 2.9.2
   SiemensSiplus Cpu 1518f-4 Pn/dp Version-
SiemensCpu 1510sp-1pn Firmware Version >= 2.5 < 2.9.2
   SiemensCpu 1510sp-1pn Version-
SiemensCpu1510sp F-1 Firmware Version >= 2.5 < 2.9.2
   SiemensCpu1510sp F-1 Version-
SiemensCpu 1511-1pn Firmware Version >= 2.5 < 2.9.2
   SiemensCpu 1511-1pn Version-
SiemensCpu 1511-1pn Firmware Version >= 2.5 < 2.9.2
   SiemensCpu 1511-1pn Version-
SiemensCpu 1511c-1 Pn Firmware Version >= 2.5 < 2.9.2
   SiemensCpu 1511c-1 Pn Version-
SiemensCpu 1511f-1pn Firmware Version >= 2.5 < 2.9.2
   SiemensCpu 1511f-1pn Version-
SiemensCpu 1511t-1pn Firmware Version >= 2.5 < 2.9.2
   SiemensCpu 1511t-1pn Version-
SiemensCpu 1511tf-1pn Firmware Version >= 2.5 < 2.9.2
   SiemensCpu 1511tf-1pn Version-
SiemensCpu 1512c-1 Pn Firmware Version >= 2.5 < 2.9.2
   SiemensCpu 1512c-1 Pn Version-
SiemensCpu 1512sp-1 Pn Firmware Version >= 2.5 < 2.9.2
   SiemensCpu 1512sp-1 Pn Version-
SiemensCpu 1512sp F-1 Pn Firmware Version >= 2.5 < 2.9.2
   SiemensCpu 1512sp F-1 Pn Version-
SiemensCpu 1513-1 Pn Firmware Version >= 2.5 < 2.9.2
   SiemensCpu 1513-1 Pn Version-
SiemensCpu 1513f-1 Pn Firmware Version >= 2.5 < 2.9.2
   SiemensCpu 1513f-1 Pn Version-
SiemensCpu 1513r-1 Pn Firmware Version >= 2.5 < 2.9.2
   SiemensCpu 1513r-1 Pn Version-
SiemensCpu 1513pro F-2 Pn Firmware Version >= 2.5 < 2.9.2
   SiemensCpu 1513pro F-2 Pn Version-
SiemensCpu 1515-2 Firmware Version >= 2.5 < 2.9.2
   SiemensCpu 1515-2 Version-
SiemensCpu 1515f-2 Firmware Version >= 2.5 < 2.9.2
   SiemensCpu 1515f-2 Version-
SiemensCpu 1515r-2 Pn Firmware Version >= 2.5 < 2.9.2
   SiemensCpu 1515r-2 Pn Version-
SiemensCpu 1515t-2 Pn Firmware Version >= 2.5 < 2.9.2
   SiemensCpu 1515t-2 Pn Version-
SiemensCpu 1515tf-2 Pn Firmware Version >= 2.5 < 2.9.2
   SiemensCpu 1515tf-2 Pn Version-
SiemensCpu 1516pro F-2 Pn Firmware Version >= 2.5 < 2.9.2
   SiemensCpu 1516pro F-2 Pn Version-
SiemensCpu 1516pro-2 Pn Firmware Version >= 2.5 < 2.9.2
   SiemensCpu 1516pro-2 Pn Version-
SiemensCpu 1516-3 Firmware Version >= 2.5 < 2.9.2
   SiemensCpu 1516-3 Version-
SiemensCpu 1516f-3 Firmware Version >= 2.5 < 2.9.2.
   SiemensCpu 1516f-3 Version-
SiemensCpu 1516t-3 Pn/dp Firmware Version >= 2.5 < 2.9.2
   SiemensCpu 1516t-3 Pn/dp Version-
SiemensCpu 1516tf-3 Pn/dp Firmware Version >= 2.5 < 2.9.2
   SiemensCpu 1516tf-3 Pn/dp Version-
SiemensCpu 1517-3 Pn/dp Firmware Version >= 2.5 < 2.9.2
   SiemensCpu 1517-3 Pn/dp Version-
SiemensCpu 1517f-3 Pn/dp Firmware Version >= 2.5 < 2.9.2
   SiemensCpu 1517f-3 Pn/dp Version-
SiemensCpu 1517t-3 Pn/dp Firmware Version >= 2.5 < 2.9.2
   SiemensCpu 1517t-3 Pn/dp Version-
SiemensCpu 1517tf-3 Pn/dp Firmware Version >= 2.5 < 2.9.2
   SiemensCpu 1517tf-3 Pn/dp Version-
SiemensCpu 1518-4 Pn/dp Firmware Version >= 2.5 < 2.9.2
   SiemensCpu 1518-4 Pn/dp Version-
SiemensCpu 1518f-4 Pn/dp Firmware Version >= 2.5 < 2.9.2
   SiemensCpu 1518f-4 Pn/dp Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.369
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.