CVE-2026-27662
CVSS 7.7 HIGH: affected devices do not properly restrict access to the web browser via the Control Panel when no corresponding… EPSS 0.2% (5º percentile).
Vulnerabilità · 138 giorni fa
L'assunto errato è che il link di aiuto su un pannello SIMATIC HMI sia una UI innocua. Sui Unified Comfort Panels interessati, un attaccante non autenticato può raggiungere il browser web incorporato se il dispositivo non è protetto dai meccanismi di sicurezza previsti, il che può esporre gli interni e rivelare backdoor o configurazioni errate.
CVSS 7.7 HIGH: affected devices do not properly restrict access to the web browser via the Control Panel when no corresponding… EPSS 0.2% (5º percentile).
1 fonte che coprono questa storia
Siemens SIMATIC Summary SIMATIC HMI Unified Comfort Panels before V21.0 are affected by a vulnerability that allows an unauthenticated attacker to access the web browser via the help link.
Part of the PlainSec briefing for 2026-05-15