PT-2020-14636 · Siemens · Sinumerik 840D Sl+3

Published

2020-09-09

·

Updated

2020-12-14

·

CVE-2020-15791

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions) SIMATIC S7-400 CPU family (incl. SIPLUS variants) (All versions) SIMATIC WinAC RTX (F) 2010 (All versions) SINUMERIK 840D sl (All versions)
Description A security issue has been found in the authentication protocol used between a client and a Programmable Logic Controller (PLC) via port 102/tcp (ISO-TSAP). The protocol does not adequately protect the password being transmitted, which could allow an attacker who intercepts the network traffic to obtain valid PLC credentials.
Recommendations For SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants), consider restricting access to port 102/tcp (ISO-TSAP) to minimize the risk of exploitation. For SIMATIC S7-400 CPU family (incl. SIPLUS variants), restrict access to the authentication protocol via port 102/tcp (ISO-TSAP) until a fix is available. For SIMATIC WinAC RTX (F) 2010, avoid using the affected authentication protocol via port 102/tcp (ISO-TSAP) until the issue is resolved. For SINUMERIK 840D sl, restrict access to the PLC credentials to prevent potential exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15791

Affected Products

Simatic S7-300 Cpu
Simatic S7-400 Pn Cpu
Simatic Winac Rtx 2010
Sinumerik 840D Sl