CVE Feed

    Dashboard / CVE / CVE-2020-15798

    CVE-2020-15798

    A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V16 Update 3a), SIMATIC HMI KTP Mobile Panels (All versions < V16 Update 3a), SINAMICS GH150 (All versions), SINAMICS GL150 (with option X30) (All versions), SINAMICS GM150 (with option X30) (All versions), SINAMICS SH150 (All versions), SINAMICS SL150 (All versions), SINAMICS SM120 (All versions), SINAMICS SM150 (All versions), SINAMICS SM150i (All versions). Affected devices with enabled telnet service do not require authentication for this service. This could allow a remote attacker to gain full access to the device. (ZDI-CAN-12046)

    Published:Feb 9, 2021
    Last Modified:Jun 2, 2026
    EPS:Feb 9, 2021
    EPSS Score:0.01669
    CVSS Score:9.8

    Affected Products

    Vendor
    Siemens
    Product
    Simatic Hmi Comfort Panels
    Vendor
    Siemens
    Product
    Simatic Hmi Comfort Panels Firmware
    Vendor
    Siemens
    Product
    Simatic Hmi Ktp Mobile Panels
    Vendor
    Siemens
    Product
    Simatic Hmi Ktp Mobile Panels Firmware
    Vendor
    Siemens
    Product
    Sinamics Gh150
    Vendor
    Siemens
    Product
    Sinamics Gh150 Firmware
    Vendor
    Siemens
    Product
    Sinamics Gl150
    Vendor
    Siemens
    Product
    Sinamics Gl150 Firmware
    Vendor
    Siemens
    Product
    Sinamics Gm150
    Vendor
    Siemens
    Product
    Sinamics Gm150 Firmware
    Vendor
    Siemens
    Product
    Sinamics Sh150
    Vendor
    Siemens
    Product
    Sinamics Sh150 Firmware
    Vendor
    Siemens
    Product
    Sinamics Sl150
    Vendor
    Siemens
    Product
    Sinamics Sl150 Firmware
    Vendor
    Siemens
    Product
    Sinamics Sm120
    Vendor
    Siemens
    Product
    Sinamics Sm120 Firmware
    Vendor
    Siemens
    Product
    Sinamics Sm150
    Vendor
    Siemens
    Product
    Sinamics Sm150 Firmware
    Vendor
    Siemens
    Product
    Sinamics Sm150i
    Vendor
    Siemens
    Product
    Sinamics Sm150i Firmware

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High