Out-of-Bounds Memory Access Vulnerability in Siemens SIMATIC HMI Products
CVE-2021-25661
7.5HIGH
Key Information:
- Vendor
- Siemens
- Status
- Vendor
- CVE Published:
- 12 May 2021
Summary
An out-of-bounds memory access vulnerability has been discovered in the SmartVNC component of the Siemens SIMATIC HMI products. This security flaw allows an attacker to exploit the vulnerability on the client side by sending specially crafted data from the server, potentially leading to a Denial-of-Service condition.
Affected Version(s)
SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) All versions < V15.1 Update 6
SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) All versions < V16 Update 4
SIMATIC HMI Comfort Panels V15 4\" - 22\" (incl. SIPLUS variants) All versions < V15.1 Update 6
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved