A vulnerability has been identified in SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants) (All versions < V16), SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions <= V16), SIMATIC HMI Mobile Panels (All versions <= V16), SIMATIC HMI Unified Comfort Panels (All versions <= V16). Affected devices insufficiently block excessive authentication attempts. This could allow a remote attacker to discover user passwords and obtain access to the Sm@rt Server via a brute-force attack.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSiemens Simatic Hmi Basic Panels 2nd Generation
HWSiemensall versionsSiemens Simatic Hmi Basic Panels 2nd Generation Firmware
OSSiemens≤ 14Siemens Simatic Hmi Comfort Panels
HWSiemensall versionsSiemens Simatic Hmi Comfort Panels Firmware
OSSiemensall versionsSiemens Simatic Hmi Mobile Panels
HWSiemensall versionsSiemens Simatic Hmi Mobile Panels Firmware
OSSiemensall versionsSiemens Simatic Hmi United Comfort Panels
HWSiemensall versionsSiemens Simatic Hmi United Comfort Panels Firmware
OSSiemensall versions
Related vulnerabilities
Brak uwierzytelnienia w usłudze telnet paneli Siemens SIMATIC HMI
Siemens SIMATIC HMI Unified Comfort Panels – pominięcie uwierzytelnienia przez obcięcie hasła
Siemens SIMATIC HMI — zakodowane hasło SNMP umożliwia przejęcie kontroli
A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V17 ...
The webserver of the affected devices contains a vulnerability that may lead to a denial of service condition...