Denial-of-Service Vulnerability in Siemens SIMATIC HMI and WinCC Products
CVE-2021-25662

7.5HIGH

Summary

A vulnerability in Siemens SIMATIC HMI Comfort Outdoor Panels and WinCC Runtime Advanced could allow an attacker to exploit improper exception handling in the SmartVNC client. If the execution process of the program is altered after a packet is sent from the server, it may lead to a Denial-of-Service condition, affecting device availability and operational integrity.

Affected Version(s)

SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) All versions < V15.1 Update 6

SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) All versions < V16 Update 4

SIMATIC HMI Comfort Panels V15 4\" - 22\" (incl. SIPLUS variants) All versions < V15.1 Update 6

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.