Siemens SINAMICS Medium Voltage Products Telnet (Update A)
SINAMICS medium-voltage drive products have a vulnerability in their integrated or connected HMI (SIMATIC HMI) image that allows unauthenticated Telnet access. Successful exploitation grants an attacker full remote access to the HMI, enabling them to read process data and issue control commands to the motor drives. Only HMI image versions prior to v16 Update 3a are affected. No firmware updates are available for the SINAMICS drive products themselves; the vulnerability must be mitigated by updating the HMI image and restricting network access to the Telnet interface.
- Network connectivity to the HMI Telnet port (port 23, or custom port if configured)
- Telnet service must be enabled on the HMI panel
- No authentication required or weak authentication configuration on the Telnet interface
Patching may require device reboot — plan for process interruption
/api/v1/advisories/331b319f-7f8f-4453-bca4-004fd6c9929cGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.