PT-2020-14632 · Siemens · Simatic Hmi Unified Comfort Panels
Published
2020-09-09
·
Updated
2021-06-08
·
CVE-2020-15787
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SIMATIC HMI Unified Comfort Panels versions prior to V16
Description
A security issue has been identified where affected devices do not properly validate authentication attempts. Specifically, the validation process can be tricked by truncating the input to match only a certain number of characters, rather than the entire string. This could enable a remote attacker to guess user passwords through a brute-force attack, potentially gaining access to the Sm@rt Server.
Recommendations
For versions prior to V16, update to a version that includes the necessary security fixes to properly validate authentication attempts.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Simatic Hmi Unified Comfort Panels