CVE-2021-25660
Description
A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI Comfort Panels V15 4\" - 22\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Panels V16 4\" - 22\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI KTP Mobile Panels V15 KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V15.1 Update 6), SIMATIC HMI KTP Mobile Panels V16 KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V16 Update 4), SIMATIC WinCC Runtime Advanced V15 (All versions < V15.1 Update 6), SIMATIC WinCC Runtime Advanced V16 (All versions < V16 Update 4). SmartVNC has an out-of-bounds memory access vulnerability that could be triggered on the server side when sending data from the client, which could result in a Denial-of-Service condition.
Affected products
12- Range: < V15.1 Update 6
- Siemens Foundation/SIMATIC HMI KTP Mobile Panels V15 KTP400F, KTP700, KTP700F, KTP900 and KTP900Fllm-createRange: < V15.1 Update 6
- Range: < V15.1 Update 6
- Range: < V15.1 Update 6
- Siemens/SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants)v5Range: All versions < V15.1 Update 6
- Siemens/SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants)v5Range: All versions < V16 Update 4
- Siemens/SIMATIC HMI Comfort Panels V15 4\" - 22\" (incl. SIPLUS variants)v5Range: All versions < V15.1 Update 6
- Siemens/SIMATIC HMI Comfort Panels V16 4\" - 22\" (incl. SIPLUS variants)v5Range: All versions < V16 Update 4
- Siemens/SIMATIC HMI KTP Mobile Panels V15 KTP400F, KTP700, KTP700F, KTP900 and KTP900Fv5Range: All versions < V15.1 Update 6
- Siemens/SIMATIC HMI KTP Mobile Panels V16 KTP400F, KTP700, KTP700F, KTP900 and KTP900Fv5Range: All versions < V16 Update 4
All versions < V15.1 Update 6+ 1 more
- (no CPE)range: All versions < V15.1 Update 6
- (no CPE)range: All versions < V16 Update 4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- cert-portal.siemens.com/productcert/pdf/ssa-538778.pdfmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.