VYPR
Unrated severityNVD Advisory· Published May 12, 2021· Updated Aug 3, 2024

CVE-2021-25661

CVE-2021-25661

Description

A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI Comfort Panels V15 4\" - 22\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Panels V16 4\" - 22\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI KTP Mobile Panels V15 KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V15.1 Update 6), SIMATIC HMI KTP Mobile Panels V16 KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V16 Update 4), SIMATIC WinCC Runtime Advanced V15 (All versions < V15.1 Update 6), SIMATIC WinCC Runtime Advanced V16 (All versions < V16 Update 4). SmartVNC has an out-of-bounds memory access vulnerability that could be triggered on the client side when sending data from the server, which could result in a Denial-of-Service condition.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An out-of-bounds memory access in SmartVNC on Siemens HMI panels and WinCC Runtime Advanced allows a remote unauthenticated attacker to trigger a denial-of-service condition.

Vulnerability

SmartVNC contains an out-of-bounds memory access vulnerability (CWE-788) that can be triggered when the server sends data to the client [1]. The affected products include SIMATIC HMI Comfort Outdoor Panels V15 and V16 (including SIPLUS variants), SIMATIC HMI Comfort Panels V15 and V16 (including SIPLUS variants), SIMATIC HMI KTP Mobile Panels V15 and V16, and SIMATIC WinCC Runtime Advanced V15 and V16. The vulnerable versions are all releases prior to V15.1 Update 6 for V15 series and all releases prior to V16 Update 4 for V16 series.

Exploitation

The vulnerability is remotely exploitable over the network without authentication and does not require user interaction [1]. An attacker can send crafted data from the SmartVNC server to the client, triggering an out-of-bounds memory access on the client side. The exact sequence of steps is not detailed in the available references, but the attack vector is network-based, targeting the SmartVNC protocol [1].

Impact

Successful exploitation results in a denial-of-service (DoS) condition on the affected device [1]. The CVSS v3 base score is 9.8 (Critical), indicating high impact on availability, confidentiality, and integrity under certain conditions, though the described vulnerability itself is limited to DoS [1].

Mitigation

Siemens has released updates to address the vulnerability: V15.1 Update 6 for V15 series and V16 Update 4 for V16 series [1]. Users should apply the updates to all affected products. The advisory was originally published February 9, 2021, and updated May 11, 2021, with no workarounds mentioned in the available references [1]. This vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog as of the publication date.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

10
  • Range: < V15.1 Update 6
  • Siemens/SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants)v5
    Range: All versions < V15.1 Update 6
  • Siemens/SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants)v5
    Range: All versions < V16 Update 4
  • Siemens/SIMATIC HMI Comfort Panels V15 4\" - 22\" (incl. SIPLUS variants)v5
    Range: All versions < V15.1 Update 6
  • Siemens/SIMATIC HMI Comfort Panels V16 4\" - 22\" (incl. SIPLUS variants)v5
    Range: All versions < V16 Update 4
  • Siemens/SIMATIC HMI KTP Mobile Panels V15 KTP400F, KTP700, KTP700F, KTP900 and KTP900Fv5
    Range: All versions < V15.1 Update 6
  • Siemens/SIMATIC HMI KTP Mobile Panels V16 KTP400F, KTP700, KTP700F, KTP900 and KTP900Fv5
    Range: All versions < V16 Update 4
  • All versions < V15.1 Update 6+ 1 more
    • (no CPE)range: All versions < V15.1 Update 6
    • (no CPE)range: All versions < V16 Update 4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.