← Vulnerability feed

Vulnerability record · CVE-2020-15786 · published 9 September 2020

CVE-2020-15786: Siemens simatic hmi basic panels 2nd generation firmware improper restriction of authentication attempts vulnerability

Siemens · Simatic Hmi Basic Panels 2nd Generation Firmware

A vulnerability has been identified in SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants) (All versions < V16), SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions <= V16), SIMATIC HMI Mobile Panels (All versions <= V16), SIMATIC HMI Unified Comfort Panels (All versions <= V16). Affected devices insufficiently block excessive authentication attempts. This could allow a remote attacker to discover user passwords and obtain access to the Sm@rt Server via a brute-force attack.

9.8 CVSS 3.1 Critical EPSS 1.5% · top 26.9% CWE-307 · Improper restriction of authentication attempts
9.8CVSS 3.1 base score, v2 5.0
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A vulnerability has been identified in SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants) (All versions < V16), SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions <= V16), SIMATIC HMI Mobile Panels (All versions <= V16), SIMATIC HMI Unified Comfort Panels (All versions <= V16). Affected devices insufficiently block excessive authentication attempts. This could allow a remote attacker to discover user passwords and obtain access to the Sm@rt Server via a brute-force attack.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-15786 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-15798Siemens simatic hmi comfort panels firmware missing authentication for critical function vulnerabilityA vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V16 Update 3a), SIMATIC HMI KTP Mobile Pane…EPSS 5.2%9.8CVE-2020-15787Siemens simatic hmi united comfort panels firmware improper authentication vulnerabilityA vulnerability has been identified in SIMATIC HMI Unified Comfort Panels (All versions <= V16). Affected devices insufficiently validate authenticat…EPSS 1.5%9.1CVE-2019-6572Siemens simatic hmi comfort panels firmware information exposure vulnerabilityA vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15.1 Update 1), SIMATIC HMI Comfort Outdoor Panels 7" & 1…EPSS 2.7%8.8CVE-2018-13814Siemens simatic hmi comfort panels firmware improper input validation vulnerabilityA vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V14), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (All ver…EPSS 1.7%8.1CVE-2018-13813Siemens simatic hmi comfort panels firmware open redirect vulnerabilityA vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15 Update 4), SIMATIC HMI Comfort Outdoor Panels 7" & 15"…EPSS 1.7%7.5CVE-2022-40227Siemens simatic hmi comfort panels firmware improper input validation vulnerabilityA vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V17 Update 4), SIMATIC HMI KTP Mobile Panel…EPSS 0.84%7.5CVE-2019-6568Siemens cp1604 firmware out-of-bounds read vulnerabilityThe webserver of the affected devices contains a vulnerability that may lead to a denial of service condition. An attacker may cause a denial of serv…EPSS 1.4%7.5CVE-2018-13812Siemens simatic hmi comfort panels firmware path traversal vulnerabilityA vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15 Update 4), SIMATIC HMI Comfort Outdoor Panels 7" & 15"…EPSS 3.6%

Source: NIST National Vulnerability Database (record CVE-2020-15786), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.