Vulnerability record · CVE-2020-7592 · published 14 July 2020
CVE-2020-7592: Siemens simatic hmi basic panels 1st generation cleartext transmission vulnerability
Siemens · Simatic Hmi Basic Panels 1st Generation
A vulnerability has been identified in SIMATIC HMI Basic Panels 1st Generation (incl. SIPLUS variants) (All versions), SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants) (All versions), SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions), SIMATIC HMI KTP700F Mobile Arctic (All versions), SIMATIC HMI Mobile Panels 2nd Generation (All versions), SIMATIC WinCC Runtime Advanced (All versions). Unencrypted communication between the configuration software and the respective device could allow an attacker to capture potential plain text communication and have access to sensitive information.
Description
A vulnerability has been identified in SIMATIC HMI Basic Panels 1st Generation (incl. SIPLUS variants) (All versions), SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants) (All versions), SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions), SIMATIC HMI KTP700F Mobile Arctic (All versions), SIMATIC HMI Mobile Panels 2nd Generation (All versions), SIMATIC WinCC Runtime Advanced (All versions). Unencrypted communication between the configuration software and the respective device could allow an attacker to capture potential plain text communication and have access to sensitive information.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://cert-portal.siemens.com/productcert/pdf/ssa-364335.pdf | Vendor Advisory |
| https://us-cert.cisa.gov/ics/advisories/icsa-20-196-04 | Third Party AdvisoryUS Government Resource |
| https://cert-portal.siemens.com/productcert/pdf/ssa-364335.pdf | Vendor Advisory |
| https://us-cert.cisa.gov/ics/advisories/icsa-20-196-04 | Third Party AdvisoryUS Government Resource |
Track CVE-2020-7592 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-7592), CISA KEV, FIRST EPSS (scores of 2026-10-05). This page is refreshed as NVD updates the record.