siemens simatic-winac-rtx-f-2010 CVE-2020-15791 vulnerability in Siemens Products
Published on September 9, 2020

A vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC S7-400 CPU family (incl. SIPLUS variants) (All versions), SIMATIC WinAC RTX (F) 2010 (All versions), SINUMERIK 840D sl (All versions). The authentication protocol between a client and a PLC via port 102/tcp (ISO-TSAP) insufficiently protects the transmitted password. This could allow an attacker that is able to intercept the network traffic to obtain valid PLC credentials.

NVD

Vulnerability Analysis

Attack Vector:
ADJACENT_NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
NONE
Availability Impact:
NONE

Weakness Type

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.


Products Associated with CVE-2020-15791

stack.watch emails you whenever new vulnerabilities are published in Siemens Simatic Winac Rtx F 2010 or Siemens Sinumerik 840d Sl. Just hit a watch button to start following.

 
 

Affected Versions

Siemens SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants): Siemens SIMATIC S7-400 CPU family (incl. SIPLUS variants): Siemens SIMATIC WinAC RTX (F) 2010: Siemens SINUMERIK 840D sl:

Exploit Probability

EPSS
0.08%
Percentile
23.97%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.