PT-2020-19641 · Siemens · Simatic Hmi Ktp700F Mobile Arctic+5

Richard Thomas

+1

·

Published

2020-07-14

·

Updated

2020-07-22

·

CVE-2020-7592

CVSS v2.0

3.3

Low

VectorAV:A/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions SIMATIC HMI Basic Panels 1st Generation (incl. SIPLUS variants) (All versions) SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants) (All versions) SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions) SIMATIC HMI KTP700F Mobile Arctic (All versions) SIMATIC HMI Mobile Panels 2nd Generation (All versions) SIMATIC WinCC Runtime Advanced (All versions)
Description A vulnerability has been identified that could allow an attacker to capture plain text communication between the configuration software and the device, potentially gaining access to sensitive information. This is due to unencrypted communication.
Recommendations For SIMATIC HMI Basic Panels 1st Generation (incl. SIPLUS variants), consider implementing encrypted communication protocols to protect data. For SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants), restrict access to the configuration software to minimize the risk of exploitation. For SIMATIC HMI Comfort Panels (incl. SIPLUS variants), ensure all communication is encrypted to prevent plain text capture. For SIMATIC HMI KTP700F Mobile Arctic, disable any features that rely on unencrypted communication until a secure method is implemented. For SIMATIC HMI Mobile Panels 2nd Generation, limit access to sensitive information by implementing secure authentication and authorization mechanisms. For SIMATIC WinCC Runtime Advanced, update the configuration software to use encrypted communication protocols.

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-7592

Affected Products

Simatic Hmi Basic Panels 1St Generation
Simatic Hmi Basic Panels 2Nd Generation
Simatic Hmi Comfort Panels
Simatic Hmi Ktp700F Mobile Arctic
Simatic Hmi Mobile Panels 2Nd Generation
Simatic Wincc Runtime Advanced