VYPR
Unrated severityNVD Advisory· Published May 12, 2021· Updated Aug 3, 2024

CVE-2021-25662

CVE-2021-25662

Description

A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI Comfort Panels V15 4\" - 22\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Panels V16 4\" - 22\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI KTP Mobile Panels V15 KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V15.1 Update 6), SIMATIC HMI KTP Mobile Panels V16 KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V16 Update 4), SIMATIC WinCC Runtime Advanced V15 (All versions < V15.1 Update 6), SIMATIC WinCC Runtime Advanced V16 (All versions < V16 Update 4). SmartVNC client fails to handle an exception properly if the program execution process is modified after sending a packet from the server, which could result in a Denial-of-Service condition.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

SmartVNC client in Siemens SIMATIC HMI panels and WinCC Runtime Advanced fails to handle an exception, allowing remote denial of service.

Vulnerability

The vulnerability resides in the SmartVNC client component of Siemens SIMATIC HMI Comfort Outdoor Panels V15 and V16, SIMATIC HMI Comfort Panels V15 and V16, SIMATIC HMI KTP Mobile Panels V15 and V16, and SIMATIC WinCC Runtime Advanced V15 and V16 (including SIPLUS variants). All versions prior to V15.1 Update 6 (for V15) and V16 Update 4 (for V16) are affected. The client fails to properly handle an exception when the program execution process is modified after receiving a packet from the server, leading to an out-of-bounds memory access [1].

Exploitation

An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted packet to the SmartVNC server. No user interaction or special privileges are required. The attack is network-based and can be carried out without prior authentication, as indicated by the CVSS v3 score of 9.8 [1]. The exact sequence involves the attacker sending a malicious packet that triggers the improper exception handling in the client, causing the denial-of-service condition.

Impact

Successful exploitation results in a denial-of-service (DoS) condition on the affected HMI panel or WinCC Runtime Advanced system. The device may become unresponsive or crash, disrupting the human-machine interface and potentially halting industrial processes. The vulnerability does not lead to code execution or information disclosure for this specific CVE, though other related CVEs in the same advisory may have different impacts [1].

Mitigation

Siemens has released updates to address this vulnerability: V15.1 Update 6 for V15 products and V16 Update 4 for V16 products. Users should apply these updates as soon as possible. No workarounds are documented. The CISA advisory (ICSA-21-131-12) provides further details and recommends upgrading to the fixed versions [1]. If immediate patching is not possible, restrict network access to the affected devices as a compensating control.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

12
  • Range: <V15.1 Update 6, <V16 Update 4
  • Range: <V15.1 Update 6, <V16 Update 4
  • Range: <V15.1 Update 6, <V16 Update 4
  • Range: <V15.1 Update 6, <V16 Update 4
  • Siemens/SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants)v5
    Range: All versions < V15.1 Update 6
  • Siemens/SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants)v5
    Range: All versions < V16 Update 4
  • Siemens/SIMATIC HMI Comfort Panels V15 4\" - 22\" (incl. SIPLUS variants)v5
    Range: All versions < V15.1 Update 6
  • Siemens/SIMATIC HMI Comfort Panels V16 4\" - 22\" (incl. SIPLUS variants)v5
    Range: All versions < V16 Update 4
  • Siemens/SIMATIC HMI KTP Mobile Panels V15 KTP400F, KTP700, KTP700F, KTP900 and KTP900Fv5
    Range: All versions < V15.1 Update 6
  • Siemens/SIMATIC HMI KTP Mobile Panels V16 KTP400F, KTP700, KTP700F, KTP900 and KTP900Fv5
    Range: All versions < V16 Update 4
  • All versions < V15.1 Update 6+ 1 more
    • (no CPE)range: All versions < V15.1 Update 6
    • (no CPE)range: All versions < V16 Update 4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.