CVE-2020-15796: Siemens SIMATIC Et 200sp Open Controller Firmware

High severity, CVSS 7.5. EPSS: 1.6% chance of exploitation in the next 30 days.

A vulnerability has been identified in SIMATIC ET 200SP Open Controller (incl. SIPLUS variants) (V20.8), SIMATIC S7-1500 Software Controller (V20.8). The web server of the affected products contains a vulnerability that could allow a remote attacker to trigger a denial-of-service condition by sending a specially crafted HTTP request.

Affected products

  • Siemens SIMATIC Et 200sp Open Controller Firmware: up to and including 20.8
  • Siemens SIMATIC s7-1500 Software Controller Firmware: up to and including 20.8

Published 2020-12-14. Last modified 2026-06-17.