Vulnerabilità · 138 giorni fa

I pannelli SIMATIC HMI espongono l'accesso del browser tramite il link di aiuto

L'assunto errato è che il link di aiuto su un pannello SIMATIC HMI sia una UI innocua. Sui Unified Comfort Panels interessati, un attaccante non autenticato può raggiungere il browser web incorporato se il dispositivo non è protetto dai meccanismi di sicurezza previsti, il che può esporre gli interni e rivelare backdoor o configurazioni errate.

CVE-2026-27662

NVD KEV

CVSS 7.7 HIGH: affected devices do not properly restrict access to the web browser via the Control Panel when no corresponding… EPSS 0.2% (5º percentile).

Cronologia

Fonti

1 fonte che coprono questa storia

Entità

Part of the PlainSec briefing for 2026-05-15

Editions

Storie correlate