First published: Wed Sep 09 2020(Updated: )
A vulnerability has been identified in SIMATIC HMI Unified Comfort Panels (All versions <= V16). Affected devices insufficiently validate authentication attempts as the information given can be truncated to match only a set number of characters versus the whole provided string. This could allow a remote attacker to discover user passwords and obtain access to the Sm@rt Server via a brute-force attack.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Simatic Hmi United Comfort Panels Firmware | ||
Siemens Simatic Hmi United Comfort Panels |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-15787.
The severity of CVE-2020-15787 is critical with a score of 9.8.
All versions of SIMATIC HMI Unified Comfort Panels <= V16 are affected.
CVE-2020-15787 affects the affected devices by insufficiently validating authentication attempts, allowing a potential unauthorized access.
Siemens has released a security advisory with recommended mitigations for CVE-2020-15787. Please refer to the provided reference for more information.