SNMP Service Disruption in SIMATIC HMI Comfort Panels and KTP Mobile Panels
CVE-2019-19276
5.3MEDIUM
Key Information:
- Vendor
Siemens
- Status
- Vendor
- CVE Published:
- 12 May 2021
What is CVE-2019-19276?
A vulnerability in the SNMP service of the SIMATIC HMI Comfort Panels (1st Generation and SIPLUS variants) and KTP Mobile Panels allows for specially crafted packets sent to UDP port 161, potentially causing the service to crash. As a result, device operation is interrupted, necessitating a manual restart to restore functionality. This vulnerability affects all versions prior to V16 Update 4, highlighting the importance of monitoring and securing network communications to prevent exploitation.
Affected Version(s)
SIMATIC HMI Comfort Panels 1st Generation (incl. SIPLUS variants) All versions < V16 Update 4
SIMATIC HMI KTP Mobile Panels All versions < V16 Update 4