Denial of Service Vulnerability in SIMATIC HMI Panels and SINAMICS Products
CVE-2021-27385

7.5HIGH

Summary

A vulnerability has been discovered in various SIMATIC HMI panels and SINAMICS products that could allow a remote attacker to exploit a flaw in the SmartVNC device layout handler on the client side. By sending specially crafted packets, an attacker could lead the system into an infinite loop, causing significant resource consumption and potentially resulting in a Denial-of-Service condition, affecting the responsiveness and availability of the impacted device.

Affected Version(s)

SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) All versions < V15.1 Update 6

SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) All versions < V16 Update 4

SIMATIC HMI Comfort Panels V15 4\" - 22\" (incl. SIPLUS variants) All versions < V15.1 Update 6

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.