CVE-2020-28397
published 2021-08-10CVE-2020-28397: A vulnerability has been identified in SIMATIC Drive Controller family (All versions V2 V2.5 V2.5 < V21.9), TIM 1531 IRC (incl. SIPLUS NET variants) (Version…
PriorityP429medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.75%
50.7th percentile
A vulnerability has been identified in SIMATIC Drive Controller family (All versions V2 V2.5 V2.5 < V21.9), TIM 1531 IRC (incl. SIPLUS NET variants) (Version V2.1). Due to an incorrect authorization check in the affected component, an attacker could extract information about access protected PLC program variables over port 102/tcp from an affected device when reading multiple attributes at once.
Affected
63 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | cpu1510sp_f-1_firmware | >= 2.5 < 2.9.2 | 2.9.2 |
| siemens | cpu_1211c_firmware | — | — |
| siemens | cpu_1212c_firmware | — | — |
| siemens | cpu_1212fc_firmware | — | — |
| siemens | cpu_1214c_firmware | — | — |
| siemens | cpu_1214fc_firmware | — | — |
| siemens | cpu_1215c_firmware | — | — |
| siemens | cpu_1215fc_firmware | — | — |
| siemens | cpu_1217c_firmware | — | — |
| siemens | cpu_1504d_tf_firmware | < 2.9.2 | 2.9.2 |
| siemens | cpu_1507d_tf_firmware | < 2.9.2 | 2.9.2 |
| siemens | cpu_1510sp-1pn_firmware | >= 2.5 < 2.9.2 | 2.9.2 |
| siemens | cpu_1511-1pn_firmware | >= 2.5 < 2.9.2 | 2.9.2 |
| siemens | cpu_1511c-1_pn_firmware | >= 2.5 < 2.9.2 | 2.9.2 |
| siemens | cpu_1511f-1pn_firmware | >= 2.5 < 2.9.2 | 2.9.2 |
| siemens | cpu_1511t-1pn_firmware | >= 2.5 < 2.9.2 | 2.9.2 |
| siemens | cpu_1511tf-1pn_firmware | >= 2.5 < 2.9.2 | 2.9.2 |
| siemens | cpu_1512c-1_pn_firmware | >= 2.5 < 2.9.2 | 2.9.2 |
| siemens | cpu_1512sp-1_pn_firmware | >= 2.5 < 2.9.2 | 2.9.2 |
| siemens | cpu_1512sp_f-1_pn_firmware | >= 2.5 < 2.9.2 | 2.9.2 |
| siemens | cpu_1513-1_pn_firmware | >= 2.5 < 2.9.2 | 2.9.2 |
| siemens | cpu_1513f-1_pn_firmware | >= 2.5 < 2.9.2 | 2.9.2 |
| siemens | cpu_1513pro_f-2_pn_firmware | >= 2.5 < 2.9.2 | 2.9.2 |
| siemens | cpu_1513r-1_pn_firmware | >= 2.5 < 2.9.2 | 2.9.2 |
| siemens | cpu_1515-2_firmware | >= 2.5 < 2.9.2 | 2.9.2 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wg3f-fv3w-mw54: A vulnerability has been identified in SIMATIC Drive Controller family (All versions V2 V2
ghsa_unreviewed·2022-05-24
CVE-2020-28397 [MEDIUM] CWE-863 GHSA-wg3f-fv3w-mw54: A vulnerability has been identified in SIMATIC Drive Controller family (All versions V2 V2
A vulnerability has been identified in SIMATIC Drive Controller family (All versions V2 V2.5 V2.5), TIM 1531 IRC (incl. SIPLUS NET variants) (Version V2.1). Due to an incorrect authorization check in the affected component, an attacker could extract information about access protected PLC program variables over port 102/tcp from an affected device when reading multiple attributes at once.
CISA ICS
Siemens SIMATIC and TIM
cisa_ics·2021-09-15·CVSS 5.3
[MEDIUM] Siemens SIMATIC and TIM
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SIMATIC and TIM
Last RevisedSeptember 15, 2021
Alert CodeICSA-21-257-23
## 1. EXECUTIVE SUMMARY
- CVSS v3 5.3
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC, TIM
- Vulnerability: Incorrect Authorization
## 2. RISK EVALUATION
Successful exploitation of this vulnerability allows an unauthenticated attacker to read PLC variables from affected devices without proper authentication under certain circumstances.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following Siemens products are affected:
- SIMATIC Drive
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-08-10
Published