CVE-2021-25661
Description
A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI Comfort Panels V15 4\" - 22\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Panels V16 4\" - 22\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI KTP Mobile Panels V15 KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V15.1 Update 6), SIMATIC HMI KTP Mobile Panels V16 KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V16 Update 4), SIMATIC WinCC Runtime Advanced V15 (All versions < V15.1 Update 6), SIMATIC WinCC Runtime Advanced V16 (All versions < V16 Update 4). SmartVNC has an out-of-bounds memory access vulnerability that could be triggered on the client side when sending data from the server, which could result in a Denial-of-Service condition.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An out-of-bounds memory access in SmartVNC on Siemens HMI panels and WinCC Runtime Advanced allows a remote unauthenticated attacker to trigger a denial-of-service condition.
Vulnerability
SmartVNC contains an out-of-bounds memory access vulnerability (CWE-788) that can be triggered when the server sends data to the client [1]. The affected products include SIMATIC HMI Comfort Outdoor Panels V15 and V16 (including SIPLUS variants), SIMATIC HMI Comfort Panels V15 and V16 (including SIPLUS variants), SIMATIC HMI KTP Mobile Panels V15 and V16, and SIMATIC WinCC Runtime Advanced V15 and V16. The vulnerable versions are all releases prior to V15.1 Update 6 for V15 series and all releases prior to V16 Update 4 for V16 series.
Exploitation
The vulnerability is remotely exploitable over the network without authentication and does not require user interaction [1]. An attacker can send crafted data from the SmartVNC server to the client, triggering an out-of-bounds memory access on the client side. The exact sequence of steps is not detailed in the available references, but the attack vector is network-based, targeting the SmartVNC protocol [1].
Impact
Successful exploitation results in a denial-of-service (DoS) condition on the affected device [1]. The CVSS v3 base score is 9.8 (Critical), indicating high impact on availability, confidentiality, and integrity under certain conditions, though the described vulnerability itself is limited to DoS [1].
Mitigation
Siemens has released updates to address the vulnerability: V15.1 Update 6 for V15 series and V16 Update 4 for V16 series [1]. Users should apply the updates to all affected products. The advisory was originally published February 9, 2021, and updated May 11, 2021, with no workarounds mentioned in the available references [1]. This vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog as of the publication date.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
10- Range: < V15.1 Update 6
- Range: < V15.1 Update 6
- Siemens/SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants)v5Range: All versions < V15.1 Update 6
- Siemens/SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants)v5Range: All versions < V16 Update 4
- Siemens/SIMATIC HMI Comfort Panels V15 4\" - 22\" (incl. SIPLUS variants)v5Range: All versions < V15.1 Update 6
- Siemens/SIMATIC HMI Comfort Panels V16 4\" - 22\" (incl. SIPLUS variants)v5Range: All versions < V16 Update 4
- Siemens/SIMATIC HMI KTP Mobile Panels V15 KTP400F, KTP700, KTP700F, KTP900 and KTP900Fv5Range: All versions < V15.1 Update 6
- Siemens/SIMATIC HMI KTP Mobile Panels V16 KTP400F, KTP700, KTP700F, KTP900 and KTP900Fv5Range: All versions < V16 Update 4
All versions < V15.1 Update 6+ 1 more
- (no CPE)range: All versions < V15.1 Update 6
- (no CPE)range: All versions < V16 Update 4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- cert-portal.siemens.com/productcert/pdf/ssa-538778.pdfmitrex_refsource_CONFIRM
- us-cert.cisa.gov/ics/advisories/icsa-21-131-12mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.