CVE-2026-27662
CVSS 7.7 HIGH: affected devices do not properly restrict access to the web browser via the Control Panel when no corresponding… EPSS 0.2% (5º percentile).
Vulnerabilità ed exploit · Attacco ad app web
L'assunto errato è che il link di aiuto su un pannello SIMATIC HMI sia una UI innocua. Sui Unified Comfort Panels interessati, un attaccante non autenticato può raggiungere il browser web incorporato se il dispositivo non è protetto dai meccanismi di sicurezza previsti, il che può esporre gli interni e rivelare backdoor o configurazioni errate.
1 fonte · 14 mag
CVSS 7.7 HIGH: affected devices do not properly restrict access to the web browser via the Control Panel when no corresponding… EPSS 0.2% (5º percentile).
CISA Advisories
Siemens SIMATIC | CISA
Siemens SIMATIC Summary SIMATIC HMI Unified Comfort Panels before V21.0 are affected by a vulnerability that allows an unauthenticated attacker to access the web browser via the help link.
originalePart of the PlainSec briefing for 2026-05-15
Every edition of this story: I pannelli SIMATIC HMI espongono l'accesso del browser tramite il link di aiuto