← Vulnerability feed

Vulnerability record · CVE-2020-15798 · published 9 February 2021

CVE-2020-15798: Siemens simatic hmi comfort panels firmware missing authentication for critical function vulnerability

Siemens · Simatic Hmi Comfort Panels Firmware

A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V16 Update 3a), SIMATIC HMI KTP Mobile Panels (All versions < V16 Update 3a), SINAMICS GH150 (All versions), SINAMICS GL150 (with option X30) (All versions), SINAMICS GM150 (with option X30) (All versions), SINAMICS SH150 (All versions), SINAMICS SL150 (All versions), SINAMICS SM120 (All versions), SINAMICS SM150 (All versions), SINAMICS SM150i (All versions). Affected devices with enabled telnet service do not require authentication for this service. This could allow a remote attacker to gain full access to the device. (ZDI-CAN-12046)

9.8 CVSS 3.1 Critical EPSS 5.2% · top 7.8% CWE-306 · Missing authentication for critical function
9.8CVSS 3.1 base score, v2 9.3
5.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
10Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

A vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V16 Update 3a), SIMATIC HMI KTP Mobile Panels (All versions < V16 Update 3a), SINAMICS GH150 (All versions), SINAMICS GL150 (with option X30) (All versions), SINAMICS GM150 (with option X30) (All versions), SINAMICS SH150 (All versions), SINAMICS SL150 (All versions), SINAMICS SM120 (All versions), SINAMICS SM150 (All versions), SINAMICS SM150i (All versions). Affected devices with enabled telnet service do not require authentication for this service. This could allow a remote attacker to gain full access to the device. (ZDI-CAN-12046)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-15798 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-27384Siemens simatic wincc runtime advanced vulnerabilityA vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIM…EPSS 2.6%9.8CVE-2020-15786Siemens simatic hmi basic panels 2nd generation firmware improper restriction of authentication attempts vulnerabilityA vulnerability has been identified in SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants) (All versions < V16), SIMATIC HMI Comfort Pane…EPSS 1.5%9.1CVE-2019-6572Siemens simatic hmi comfort panels firmware information exposure vulnerabilityA vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15.1 Update 1), SIMATIC HMI Comfort Outdoor Panels 7" & 1…EPSS 2.7%8.8CVE-2018-13814Siemens simatic hmi comfort panels firmware improper input validation vulnerabilityA vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V14), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (All ver…EPSS 1.7%8.1CVE-2018-13813Siemens simatic hmi comfort panels firmware open redirect vulnerabilityA vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15 Update 4), SIMATIC HMI Comfort Outdoor Panels 7" & 15"…EPSS 1.7%7.5CVE-2022-40227Siemens simatic hmi comfort panels firmware improper input validation vulnerabilityA vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V17 Update 4), SIMATIC HMI KTP Mobile Panel…EPSS 0.84%7.5CVE-2021-27383Siemens simatic wincc runtime advanced allocation without limits vulnerabilityA vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIM…EPSS 1.8%7.5CVE-2021-27385Siemens simatic wincc runtime advanced uncontrolled resource consumption vulnerabilityA vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIM…EPSS 2.6%

Source: NIST National Vulnerability Database (record CVE-2020-15798), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.