#VU28932 Missing Authentication for Critical Function in LOGO!8 BM - CVE-2020-7589
Published: June 10, 2020 / Updated: June 10, 2020
LOGO!8 BM
Siemens
Description
The vulnerability allows a remote attacker to bypass authentication checks.
The vulneability exists due to the affected product is missing authentication in the TDE service functionality in "NFSAccess" and "DELETEPROG" functions. A remote attacker with access to Port 135/TCP can read and modify the device configuration and obtain project files from the devices.
Remediation
External links
- https://ics-cert.us-cert.gov/advisories/icsa-20-161-03
- https://cert-portal.siemens.com/productcert/pdf/ssa-817401.pdf
- https://talosintelligence.com/vulnerability_reports/TALOS-2020-1026
- https://talosintelligence.com/vulnerability_reports/TALOS-2020-1025
- https://talosintelligence.com/vulnerability_reports/TALOS-2020-1024