First published: Wed Sep 09 2020(Updated: )
A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC S7-400 CPU family (incl. SIPLUS variants) (All versions), SIMATIC WinAC RTX (F) 2010 (All versions), SINUMERIK 840D sl (All versions). The authentication protocol between a client and a PLC via port 102/tcp (ISO-TSAP) insufficiently protects the transmitted password. This could allow an attacker that is able to intercept the network traffic to obtain valid PLC credentials.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens SIMATIC S7-300 CPU 312 firmware | ||
Siemens SIMATIC S7-300 CPU 312 firmware | ||
siemens SIMATIC S7-300 CPU 314 firmware | ||
siemens SIMATIC S7-300 CPU 314 | ||
siemens SIMATIC S7-300 CPU 315-2 DP firmware | ||
siemens SIMATIC S7-300 CPU 315-2 DP | ||
Siemens SIMATIC S7-300 CPU 315-2 PN Firmware | ||
Siemens SIMATIC S7-300 CPU 315-2 PN Firmware | ||
siemens SIMATIC S7-300 CPU 317-2 pn firmware | ||
Siemens SIMATIC S7-300 CPU 317-2 PN | ||
siemens SIMATIC S7-300 CPU 317-2 DP firmware | ||
Siemens SIMATIC S7-300 CPU 317-2 PN | ||
Siemens SIMATIC S7-300 CPU 315f-2 dp firmware | ||
Siemens SIMATIC S7-300 CPU 315f-2 dp firmware | ||
Siemens SIMATIC S7-300 CPU | ||
Siemens SIMATIC S7-300 CPU | ||
Siemens SIMATIC S7-300 CPU 317F-2 PN | ||
Siemens SIMATIC S7-300 CPU 317F-2 PN | ||
Siemens SIMATIC S7-300 CPU 317F-2 DP | ||
Siemens SIMATIC S7-300 CPU 317f-2 DP Firmware | ||
siemens SIMATIC S7-400 CPU 412 firmware | ||
Siemens SIMATIC S7-400 CPU 412 | ||
Siemens SIMATIC S7-400 CPU 414 firmware | ||
Siemens SIMATIC S7-400 CPU 414 firmware | ||
Siemens SIMATIC S7-400 CPU 416 firmware | ||
Siemens SIMATIC S7-400 CPU 416 firmware | ||
Siemens SIMATIC S7-400 CPU 417 firmware | ||
Siemens SIMATIC S7-400 CPU 417 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-15791 is medium with a CVSS score of 6.5.
CVE-2020-15791 affects SIMATIC S7-300 CPU family, SIMATIC S7-400 CPU family, SIMATIC WinAC RTX (F) 2010, and SINUMERIK 840D sl.
Siemens Simatic S7-300 Cpu 312 is not vulnerable to CVE-2020-15791.
The Common Weakness Enumeration (CWE) ID of CVE-2020-15791 is 522.
To fix CVE-2020-15791, it is recommended to apply the security patches provided by Siemens.