Heap Allocation Leak in Siemens HMI Panels and SINAMICS Devices
CVE-2021-27386

7.5HIGH

What is CVE-2021-27386?

A vulnerability in Siemens SmartVNC affects several SIMATIC HMI and SINAMICS devices, resulting in a heap allocation leak in the device layout handler on the client side. This flaw can potentially cause a Denial-of-Service (DoS) condition, impacting device availability and operations. Affected products include various models of HMI Comfort Outdoor Panels, KTP Mobile Panels, WinCC Runtime, and multiple SINAMICS ranges. It is crucial for users and system administrators to address this vulnerability through updates and implement appropriate security measures to safeguard their systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) All versions < V15.1 Update 6

SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) All versions < V16 Update 4

SIMATIC HMI Comfort Panels V15 4\" - 22\" (incl. SIPLUS variants) All versions < V15.1 Update 6

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.