A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). A service available on port 10005/tcp of the affected devices could allow complete access to all services without authorization. An attacker could gain full control over an affected device, if he has access to this service. The system manual recommends to protect access to this port.
References
Link | Resource |
---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-480824.pdf | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2020-12-14 13:15
Updated : 2020-12-16 11:01
NVD link : CVE-2020-25228
Mitre link : CVE-2020-25228
JSON object : View
CWE
CWE-306
Missing Authentication for Critical Function
Products Affected
siemens
- logo\!_8_bm_firmware
- logo\!_8_bm