CVE-2020-15796: High severity siemens simatic et 200sp open controller vulnerability
A vulnerability has been identified in SIMATIC ET 200SP Open Controller (incl. SIPLUS variants) (V20.8), SIMATIC S7-1500 Software Controller (V20.8). The web server of the affected products contains a vulnerability that could allow a remote attacker to trigger a denial-of-service condition by sending a specially crafted HTTP request.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-15796?
CVE-2020-15796 is a vulnerability identified in SIMATIC ET 200SP Open Controller (incl. SIPLUS variants) (V20.8) and SIMATIC S7-1500 Software Controller (V20.8), where the web server of the affected products contains a vulnerability that could allow a remote attacker to trigger a denial-of-service condition.
How severe is CVE-2020-15796?
CVE-2020-15796 has a severity rating of 7.5 (high).
Which products are affected by CVE-2020-15796?
SIMATIC ET 200SP Open Controller (incl. SIPLUS variants) (V20.8) and SIMATIC S7-1500 Software Controller (V20.8) are affected by CVE-2020-15796.
How can a remote attacker exploit CVE-2020-15796?
A remote attacker can exploit CVE-2020-15796 by sending specially crafted requests to the web server, triggering a denial-of-service condition.
Is there a fix for CVE-2020-15796?
Yes, Siemens has provided a security advisory with mitigation measures for CVE-2020-15796. Please refer to the official reference link for more information.