Publication Date: 2020-09-08
Last Update: 2021-06-08
Current Version: V1.3
CVSS v3.1 Base Score: 6.5

Affected Product and Versions Remediation
SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants):
All versions < V16
only affected by CVE-2020-15786
Update to V16 Update 3
https://support.industry.siemens.com/cs/ww/en/view/109775861
SIMATIC HMI Comfort Panels (incl. SIPLUS variants):
All versions <= V16
only affected by CVE-2020-15786
Update to V16 Update 3
https://support.industry.siemens.com/cs/ww/en/view/109775861
SIMATIC HMI Mobile Panels:
All versions <= V16
only affected by CVE-2020-15786
Update to V16 Update 3
https://support.industry.siemens.com/cs/ww/en/view/109775861
SIMATIC HMI Unified Comfort Panels:
All versions <= V16
Update to V16 Update 5
https://support.industry.siemens.com/cs/ww/en/view/109746530

CVSS v3.1 Base Score 6.5
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:O/RC:C
CWE: CWE-307: Improper Restriction of Excessive Authentication Attempts

CVSS v3.1 Base Score 5.3
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:U/RC:C
CWE: CWE-305: Authentication Bypass by Primary Weakness

https://www.siemens.com/cert/advisories