VYPR
Critical severity9.8NVD Advisory· Published Feb 9, 2021· Updated Jun 2, 2026

CVE-2020-15798

CVE-2020-15798

Description

Siemens SIMATIC HMI panels and certain SINAMICS drives lack authentication for the Telnet service, enabling remote attackers to gain full device access.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Siemens SIMATIC HMI panels and certain SINAMICS drives lack authentication for the Telnet service, enabling remote attackers to gain full device access.

Vulnerability

The vulnerability resides in the Telnet service of Siemens SIMATIC HMI Comfort Panels (including SIPLUS variants) and SIMATIC HMI KTP Mobile Panels (all versions before V16 Update 3a), as well as SINAMICS GH150, GL150 (with option X30), GM150 (with option X30), SH150, SL150, SM120, SM150, and SM150i drives (all versions) [1]. Affected devices with the Telnet service enabled do not require authentication, corresponding to CWE-306 (Missing Authentication for Critical Function). Telnet is disabled by default on HMI panels [1]; the exact default state on SINAMICS drives is not specified in the available references.

Exploitation

An attacker with network access to the affected device can exploit the missing authentication by simply connecting to the Telnet port (typically TCP/23) [1]. No authentication, user interaction, or prior privileges are required. The attack is remotely exploitable with low skill level [1]. The CVSS vector string indicates high attack complexity (AC:H) [1], which may imply network-level protections or other mitigations are expected to be in place, but the reference does not elaborate.

Impact

Successful exploitation grants the attacker full access to the device [1]. This results in compromise of confidentiality, integrity, and availability, as the attacker can read, modify, or disrupt device configuration and operations. The CVSS v3 base score is 8.1 (High) [1]. Critical infrastructure sectors such as Critical Manufacturing may be affected [1].

Mitigation

Siemens has released updates for the HMI panels: users should update to V16 Update 3a or later [1]. For SINAMICS drives listed, the advisory notes all versions are affected, and no fix is indicated as of the publication date [1]. As a workaround, disable Telnet on HMI panels if it is enabled [1]. Siemens also recommends protecting network access with appropriate mechanisms, such as firewalls and VPNs [1]. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog as of this writing.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

13

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

3

News mentions

0

No linked articles in our index yet.