PT-2021-7540 · Siemens · Simatic Hmi Comfort Outdoor Panels+8
Published
2021-05-11
·
Updated
2021-12-16
·
CVE-2021-27384
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SIMATIC HMI Comfort Outdoor Panels versions prior to V15.1 Update 6
SIMATIC HMI Comfort Outdoor Panels versions prior to V16 Update 4
SIMATIC HMI Comfort Panels versions prior to V15.1 Update 6
SIMATIC HMI Comfort Panels versions prior to V16 Update 4
SIMATIC HMI KTP Mobile Panels versions prior to V15.1 Update 6
SIMATIC HMI KTP Mobile Panels versions prior to V16 Update 4
SIMATIC WinCC Runtime Advanced versions prior to V15.1 Update 6
SIMATIC WinCC Runtime Advanced versions prior to V16 Update 4
SINAMICS GH150 (all versions)
SINAMICS GL150 (with option X30) (all versions)
SINAMICS GM150 (with option X30) (all versions)
SINAMICS SH150 (all versions)
SINAMICS SL150 (all versions)
SINAMICS SM120 (all versions)
SINAMICS SM150 (all versions)
SINAMICS SM150i (all versions)
Description
The issue is caused by an out-of-bounds memory access vulnerability in the device layout handler, which can potentially result in code execution. This vulnerability affects various Siemens products, including SIMATIC and SINAMICS. The vulnerability can be exploited by a remote attacker, allowing them to execute arbitrary code.
Recommendations
For SIMATIC HMI Comfort Outdoor Panels versions prior to V15.1 Update 6, update to V15.1 Update 6 or later.
For SIMATIC HMI Comfort Outdoor Panels versions prior to V16 Update 4, update to V16 Update 4 or later.
For SIMATIC HMI Comfort Panels versions prior to V15.1 Update 6, update to V15.1 Update 6 or later.
For SIMATIC HMI Comfort Panels versions prior to V16 Update 4, update to V16 Update 4 or later.
For SIMATIC HMI KTP Mobile Panels versions prior to V15.1 Update 6, update to V15.1 Update 6 or later.
For SIMATIC HMI KTP Mobile Panels versions prior to V16 Update 4, update to V16 Update 4 or later.
For SIMATIC WinCC Runtime Advanced versions prior to V15.1 Update 6, update to V15.1 Update 6 or later.
For SIMATIC WinCC Runtime Advanced versions prior to V16 Update 4, update to V16 Update 4 or later.
For SINAMICS products, contact the vendor for specific guidance on mitigation or resolution, as all versions are affected.
Fix
Access of Memory Location After End of Buffer
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simatic Hmi Comfort Outdoor Panels
Simatic Hmi Comfort Panels
Simatic Hmi Ktp Mobile Panels
Simatic Wincc Runtime Advanced
Sinamics Gh150
Sinamics Sl150
Sinamics Sm150
Sinamics Sm120
Sinamics Sm150I