A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). A service available on port 10005/tcp of the affected devices could allow complete access to all services without authorization. An attacker could gain full control over an affected device, if he has access to this service. The system manual recommends to protect access to this port.
References
Link | Resource |
---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-480824.pdf | Vendor Advisory |
https://cert-portal.siemens.com/productcert/pdf/ssa-480824.pdf | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 05:17
Type | Values Removed | Values Added |
---|---|---|
References | () https://cert-portal.siemens.com/productcert/pdf/ssa-480824.pdf - Vendor Advisory |
Information
Published : 2020-12-14 21:15
Updated : 2024-11-21 05:17
NVD link : CVE-2020-25228
Mitre link : CVE-2020-25228
CVE.ORG link : CVE-2020-25228
JSON object : View
Products Affected
siemens
- logo\!_8_bm_firmware
- logo\!_8_bm
CWE
CWE-306
Missing Authentication for Critical Function