QID 590442

Date Published: 2021-09-07

QID 590442: Siemens SIMATIC HMI Products (Update A) Multiple Vulnerabilities (ICSA-20-252-06)

AFFECTED PRODUCTS
The following versions of Siemens SIMATIC HMI Products are affected:
SIMATIC HMI Basic Panels, 2nd Generation (incl. SIPLUS variants): All versions prior to v16
SIMATIC HMI Comfort Panels (incl. SIPLUS variants): All versions up to and including v16
SIMATIC HMI Mobile Panels: All versions up to and including v16
SIMATIC HMI United Comfort Panels: All versions up to and including v16

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version using passive scanning

Successful exploitation of these vulnerabilities could allow a remote attacker to discover user passwords and obtain access to the Sm@rt Server via a brute-force attack.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-20-252-06 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590442

    Software Advisories
    Advisory ID Software Component Link
    ICSA-20-252-06 URL Logo www.us-cert.gov/ics/advisories/ICSA-20-252-06