Unrated severityNVD Advisory· Published Sep 9, 2020· Updated Aug 4, 2024
CVE-2020-15791
CVE-2020-15791
Description
A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC S7-400 CPU family (incl. SIPLUS variants) (All versions), SIMATIC WinAC RTX (F) 2010 (All versions), SINUMERIK 840D sl (All versions). The authentication protocol between a client and a PLC via port 102/tcp (ISO-TSAP) insufficiently protects the transmitted password. This could allow an attacker that is able to intercept the network traffic to obtain valid PLC credentials.
Affected products
7all versions+ 1 more
- (no CPE)range: all versions
- (no CPE)range: All versions
- Range: all versions
- Range: all versions
- Siemens Foundation/SIMATIC S7-1500 CPU family (incl. related ET200 CPUs and SIPLUS variants)cpe-rescueRange: All versions
- Range: All versions
- Range: All versions
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- cert-portal.siemens.com/productcert/pdf/ssa-381684.pdfmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.