Siemens SIMATIC

Summary

Siemens SIMATIC HMI Unified Comfort Panels before version V21.0 contain a vulnerability that allows unauthenticated attackers to access the web browser via the help link. This could lead to unauthorized access and potential misconfigurations. Siemens has released updated versions to address this issue.

IFF Assessment

FOE

This vulnerability allows unauthenticated attackers to gain access, potentially leading to misconfigurations and backdoors, which is detrimental to system security.

Severity

7.7 High

The vulnerability allows an unauthenticated attacker to access the web browser, potentially leading to unauthorized access and misconfigurations, indicating a high severity.

Defender Context

This vulnerability affects industrial control systems (ICS) and could allow attackers to compromise critical infrastructure. Defenders should prioritize patching these Siemens SIMATIC devices to the latest versions to prevent unauthorized access and potential operational disruptions.

Read Full Story →