Telnet service left enabled and without a password on SIMATIC HMI Comfort Panels
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-31337 | The Telnet service of the SIMATIC HMI Comfort Panels system component in affected products does not require authentication, which may allow a remote attacker to The Telnet service of the SIMATIC HMI Comfort Panels system component in affected products does not require authentication, which may allow a remote attacker to gain access to the device if the service is enabled. Telnet is disabled by default on the SINAMICS Medium Voltage Products (SINAMICS SL150: All versions, SINAMICS SM150: All versions, SINAMICS SM150i: All versions). NVD description · AI analysis pending | 9.8 | 2% |
| — |
Full article245 words · extracted from therecord.media · click to collapse
Siemens SIMATIC HMI Comfort Panels, devices meant to provide visualization of data received from industrial equipment, are exposing their Telnet service without any form of authentication, security researchers have discovered. The bug has industrial security experts worried as they fear this misconfiguration could lead to scenarios where threat actors could remotely access the SIMATIC panels and tamper with the data they display.— Ralph Langner (@langnergroup) June 28, 2021
No previous article
No new articles
Catalin Cimpanu
is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/telnet-service-left-enabled-and-without-a-password-on-simatic-hmi-comfort-panels