Unknown
CVE-2021-25661
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2021-25661
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\” & 15\” (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\” & 15\” (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI Comfort Panels V15 4\” – 22\” (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Panels V16 4\” – 22\” (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI KTP Mobile Panels V15 KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V15.1 Update 6), SIMATIC HMI KTP Mobile Panels V16 KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V16 Update 4), SIMATIC WinCC Runtime Advanced V15 (All versions < V15.1 Update 6), SIMATIC WinCC Runtime Advanced V16 (All versions < V16 Update 4). SmartVNC has an out-of-bounds memory access vulnerability that could be triggered on the client side when sending data from the server, which could result in a Denial-of-Service condition.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- simatic hmi comfort outdoor panels 15" firmware,
- simatic hmi comfort outdoor panels 15" firmware 15.1,
- simatic hmi comfort outdoor panels 15" firmware 16,
- simatic hmi comfort outdoor panels 7" firmware,
- simatic hmi comfort outdoor panels 7" firmware 15.1,
- simatic hmi comfort outdoor panels 7" firmware 16,
- simatic hmi comfort panels 22" firmware,
- simatic hmi comfort panels 22" firmware 15.1,
- simatic hmi comfort panels 22" firmware 16,
- simatic hmi comfort panels 4" firmware,
- simatic hmi comfort panels 4" firmware 15.1,
- simatic hmi comfort panels 4" firmware 16,
- simatic hmi ktp mobile panels ktp400f firmware,
- simatic hmi ktp mobile panels ktp400f firmware 15.1,
- simatic hmi ktp mobile panels ktp400f firmware 16,
- simatic hmi ktp mobile panels ktp700 firmware,
- simatic hmi ktp mobile panels ktp700 firmware 15.1,
- simatic hmi ktp mobile panels ktp700 firmware 16,
- simatic hmi ktp mobile panels ktp700f firmware,
- simatic hmi ktp mobile panels ktp700f firmware 15.1,
- simatic hmi ktp mobile panels ktp700f firmware 16,
- simatic hmi ktp mobile panels ktp900 firmware,
- simatic hmi ktp mobile panels ktp900 firmware 15.1,
- simatic hmi ktp mobile panels ktp900 firmware 16,
- simatic hmi ktp mobile panels ktp900f firmware,
- simatic hmi ktp mobile panels ktp900f firmware 15.1,
- simatic hmi ktp mobile panels ktp900f firmware 16,
- simatic wincc runtime advanced,
- simatic wincc runtime advanced 15.1,
- simatic wincc runtime advanced 16
References
Miscellaneous
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: