CVE-2021-27384
Description
A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI Comfort Panels V15 4\" - 22\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Panels V16 4\" - 22\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI KTP Mobile Panels V15 KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V15.1 Update 6), SIMATIC HMI KTP Mobile Panels V16 KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V16 Update 4), SIMATIC WinCC Runtime Advanced V15 (All versions < V15.1 Update 6), SIMATIC WinCC Runtime Advanced V16 (All versions < V16 Update 4), SINAMICS GH150 (All versions), SINAMICS GL150 (with option X30) (All versions), SINAMICS GM150 (with option X30) (All versions), SINAMICS SH150 (All versions), SINAMICS SL150 (All versions), SINAMICS SM120 (All versions), SINAMICS SM150 (All versions), SINAMICS SM150i (All versions). SmartVNC has an out-of-bounds memory access vulnerability in the device layout handler, represented by a binary data stream on client side, which can potentially result in code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An out-of-bounds memory access in SmartVNC's device layout handler affects Siemens SIMATIC HMI, WinCC, and SINAMICS products, potentially enabling remote code execution.
Vulnerability
A out-of-bounds memory access vulnerability exists in the device layout handler of SmartVNC, where the client processes a binary data stream. The affected products include SIMATIC HMI Comfort Outdoor Panels V15 and V16 (7" & 15", including SIPLUS variants) with all versions prior to V15.1 Update 6 or V16 Update 4, SIMATIC HMI Comfort Panels V15 and V16 (4" - 22", including SIPLUS variants) with all versions prior to V15.1 Update 6 or V16 Update 4, SIMATIC HMI KTP Mobile Panels V15 and V16 (KTP400F, KTP700, KTP700F, KTP900, KTP900F) with all versions prior to V15.1 Update 6 or V16 Update 4, SIMATIC WinCC Runtime Advanced V15 and V16 with all versions prior to V15.1 Update 6 or V16 Update 4, and multiple SINAMICS medium-voltage drives (GH150, GL150, GM150, SH150, SL150, SM120, SM150, SM150i) in all versions [1].
Exploitation
An attacker can exploit this vulnerability remotely over the network without requiring authentication or user interaction [1]. The attacker sends a crafted binary data stream to the SmartVNC client, triggering an out-of-bounds memory access in the device layout handler. The low attack complexity means no special conditions or privileges are necessary [1].
Impact
Successful exploitation could allow the attacker to execute arbitrary code with the privileges of the affected application, potentially leading to a full system compromise [1]. This includes consequences such as remote code execution, information disclosure, and denial-of-service conditions [1].
Mitigation
Siemens has released updates for the affected SIMATIC HMI and WinCC products: V15.1 Update 6 for V15 products and V16 Update 4 for V16 products [1]. As of the advisory publication date (May 12, 2021), no fixes were available for the SINAMICS medium-voltage drives, and users were advised to apply defense-in-depth measures and restrict network access [1].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
18- Siemens Foundation/SIMATIC HMI Comfort Outdoor Panels V15 7" & 15" (incl. SIPLUS variants)llm-createRange: < V15.1 Update 6
- Range: < V15.1 Update 6
- Siemens/SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants)v5Range: All versions < V15.1 Update 6
- Siemens/SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants)v5Range: All versions < V16 Update 4
- Siemens/SIMATIC HMI Comfort Panels V15 4\" - 22\" (incl. SIPLUS variants)v5Range: All versions < V15.1 Update 6
- Siemens/SIMATIC HMI Comfort Panels V16 4\" - 22\" (incl. SIPLUS variants)v5Range: All versions < V16 Update 4
- Siemens/SIMATIC HMI KTP Mobile Panels V15 KTP400F, KTP700, KTP700F, KTP900 and KTP900Fv5Range: All versions < V15.1 Update 6
- Siemens/SIMATIC HMI KTP Mobile Panels V16 KTP400F, KTP700, KTP700F, KTP900 and KTP900Fv5Range: All versions < V16 Update 4
All versions < V15.1 Update 6+ 1 more
- (no CPE)range: All versions < V15.1 Update 6
- (no CPE)range: All versions < V16 Update 4
- Range: All versions
- Siemens/SINAMICS GL150 (with option X30)v5Range: All versions
- Siemens/SINAMICS GM150 (with option X30)v5Range: All versions
All versions+ 3 more
- (no CPE)range: All versions
- (no CPE)range: All versions
- (no CPE)range: All versions
- (no CPE)range: All versions
- Range: All versions
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- cert-portal.siemens.com/productcert/pdf/ssa-286838.pdfmitrex_refsource_MISC
- cert-portal.siemens.com/productcert/pdf/ssa-538778.pdfmitrex_refsource_MISC
- us-cert.cisa.gov/ics/advisories/icsa-21-131-11mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.