PT-2020-14636 · Siemens · Sinumerik 840D Sl+3
Published
2020-09-09
·
Updated
2020-12-14
·
CVE-2020-15791
CVSS v3.1
6.5
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions)
SIMATIC S7-400 CPU family (incl. SIPLUS variants) (All versions)
SIMATIC WinAC RTX (F) 2010 (All versions)
SINUMERIK 840D sl (All versions)
Description
A security issue has been found in the authentication protocol used between a client and a Programmable Logic Controller (PLC) via port 102/tcp (ISO-TSAP). The protocol does not adequately protect the password being transmitted, which could allow an attacker who intercepts the network traffic to obtain valid PLC credentials.
Recommendations
For SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants), consider restricting access to port 102/tcp (ISO-TSAP) to minimize the risk of exploitation.
For SIMATIC S7-400 CPU family (incl. SIPLUS variants), restrict access to the authentication protocol via port 102/tcp (ISO-TSAP) until a fix is available.
For SIMATIC WinAC RTX (F) 2010, avoid using the affected authentication protocol via port 102/tcp (ISO-TSAP) until the issue is resolved.
For SINUMERIK 840D sl, restrict access to the PLC credentials to prevent potential exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simatic S7-300 Cpu
Simatic S7-400 Pn Cpu
Simatic Winac Rtx 2010
Sinumerik 840D Sl