Siemens SINAMICS S/G controllers with firmware before 4.6.11 do not require authentication for FTP and TELNET sessions, which allows remote attackers to bypass intended access restrictions via TCP traffic to port (1) 21 or (2) 23.
AV:N/AC:L/Au:N/C:C/I:C/A:CSiemens Sinamics G110
HWSiemensall versionsSiemens Sinamics G110d
HWSiemensall versionsSiemens Sinamics G120
HWSiemensall versionsSiemens Sinamics G120c
HWSiemensall versionsSiemens Sinamics G120d
HWSiemensall versionsSiemens Sinamics G120p
HWSiemensall versionsSiemens Sinamics G130
HWSiemensall versionsSiemens Sinamics G150
HWSiemensall versionsSiemens Sinamics G180
HWSiemensall versionsSiemens Sinamics S110
HWSiemensall versionsSiemens Sinamics S120
HWSiemensall versionsSiemens Sinamics S120cm
HWSiemensall versionsSiemens Sinamics S150
HWSiemensall versionsSiemens Sinamics S\/g Family Firmware
OSSiemens≤ 4.6
Related vulnerabilities
A vulnerability has been identified in SIMATIC PC-Station Plus (All versions), SIMATIC S7-400 CPU 412-2 PN V7 ...
A vulnerability has been identified in SIMATIC PC-Station Plus (All versions), SIMATIC S7-400 CPU 412-2 PN V7 ...
An attacker with network access to an affected product may cause a denial of service condition by breaking the...
The webserver of the affected devices contains a vulnerability that may lead to a denial of service condition...
Specially crafted packets sent to port 161/udp could cause a denial of service condition. The affected devices...