Out-of-bounds Memory Access in Siemens SIMATIC HMI and WinCC Products
CVE-2021-25660

7.5HIGH

Summary

A vulnerability has been identified in Siemens SIMATIC HMI and WinCC products that allows for out-of-bounds memory access via the SmartVNC component. This can be exploited on the server side by sending specially crafted data from the client, potentially leading to a Denial-of-Service condition. Affected versions are less than V15.1 Update 6 for V15 and less than V16 Update 4 for V16 across various HMI and runtime products.

Affected Version(s)

SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) All versions < V15.1 Update 6

SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) All versions < V16 Update 4

SIMATIC HMI Comfort Panels V15 4\" - 22\" (incl. SIPLUS variants) All versions < V15.1 Update 6

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.