#VU46521 Insufficiently protected credentials in SIMATIC S7-300 and SIMATIC S7-400 - CVE-2020-15791
Published: September 9, 2020
SIMATIC S7-300
SIMATIC S7-400
Siemens
Description
The vulnerability allows a remote attacker to gain access to sensitive information on the system.
The vulnerability exists due to the authentication protocol between a client and a PLC via Port 102/TCP (ISO-TSAP) insufficiently protects the transmitted password. A remote attacker on the local network can obtain valid PLC credentials.