PT-2020-14632 · Siemens · Simatic Hmi Unified Comfort Panels

Published

2020-09-09

·

Updated

2021-06-08

·

CVE-2020-15787

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions SIMATIC HMI Unified Comfort Panels versions prior to V16
Description A security issue has been identified where affected devices do not properly validate authentication attempts. Specifically, the validation process can be tricked by truncating the input to match only a certain number of characters, rather than the entire string. This could enable a remote attacker to guess user passwords through a brute-force attack, potentially gaining access to the Sm@rt Server.
Recommendations For versions prior to V16, update to a version that includes the necessary security fixes to properly validate authentication attempts.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15787

Affected Products

Simatic Hmi Unified Comfort Panels