CVE-2020-15787: Critical severity siemens simatic hmi unified comfort panels vulnerability
A vulnerability has been identified in SIMATIC HMI Unified Comfort Panels (All versions <= V16). Affected devices insufficiently validate authentication attempts as the information given can be truncated to match only a set number of characters versus the whole provided string. This could allow a remote attacker to discover user passwords and obtain access to the Sm@rt Server via a brute-force attack.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-15787.
What is the severity of CVE-2020-15787?
The severity of CVE-2020-15787 is critical with a score of 9.8.
Which software versions are affected by CVE-2020-15787?
All versions of SIMATIC HMI Unified Comfort Panels <= V16 are affected.
How does CVE-2020-15787 affect the affected devices?
CVE-2020-15787 affects the affected devices by insufficiently validating authentication attempts, allowing a potential unauthorized access.
Is there a fix for CVE-2020-15787?
Siemens has released a security advisory with recommended mitigations for CVE-2020-15787. Please refer to the provided reference for more information.