Siemens SIMATIC HMI Unified Comfort Panels Control Panel Escape Vulnerability

Vulnerability

A vulnerability exists in Siemens SIMATIC HMI Unified Comfort Panels, both Hygienic and Standard families, prior to version 21.0. The issue arises because affected devices do not adequately restrict access to the web browser through the Control Panel, when no appropriate security measures are implemented. This flaw could enable an unauthenticated attacker to access the web browser, potentially leading to the discovery of backdoors, unauthorized actions, or exploitation of misconfigurations that could further compromise the system.

Impact

Exploitation of this vulnerability could allow unauthorized access to the web browser via the Control Panel, potentially leading to the discovery and exploitation of backdoors, unauthorized actions, or misconfigurations that could compromise the system.

Remediation

Siemens has released new versions for the affected products and recommends updating to the latest versions. Specific product remediations or mitigations can be found in the Siemens Security Advisory SSA-387223. General security recommendations include protecting network access to devices with appropriate mechanisms and following Siemens' operational guidelines for Industrial Security.

Added: May 12, 2026, 10:28 AM
Updated: May 12, 2026, 10:28 AM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
1.3
exploitability
2.9
remediation
8.3
relevance
8.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.