Heap Allocation Leak in SIMATIC HMI and SINAMICS Products by Siemens
CVE-2021-27383

7.5HIGH

Summary

A heap allocation leak vulnerability exists in the SmartVNC server Tight encoder within various SIMATIC HMI and SINAMICS products. This flaw could potentially allow an attacker to exploit the affected devices, leading to a Denial-of-Service condition. Specifically, versions of the SIMATIC HMI Comfort Outdoor Panels, Comfort Panels, KTP Mobile Panels, and WinCC Runtime Advanced, as well as multiple SINAMICS products, are susceptible if they are below the specified version updates. It is crucial for users to apply the necessary updates to mitigate this risk.

Affected Version(s)

SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) All versions < V15.1 Update 6

SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) All versions < V16 Update 4

SIMATIC HMI Comfort Panels V15 4\" - 22\" (incl. SIPLUS variants) All versions < V15.1 Update 6

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.