Telnet service left enabled and without a password on SIMATIC HMI Comfort Panels

From therecord.media

Telnet service left enabled and without a password on SIMATIC HMI Comfort Panels

Siemens SIMATIC HMI Comfort Panels, devices meant to provide visualization of data received from industrial equipment, are exposing their Telnet service without any form of authentication, security researchers have discovered.

The bug has industrial security experts worried as they fear this misconfiguration could lead to scenarios where threat actors could remotely access the SIMATIC panels and tamper with the data they display.

Read more…