CVE-2021-25660
published 2021-05-12CVE-2021-25660: A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.96%
57.4th percentile
A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI Comfort Panels V15 4\" - 22\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Panels V16 4\" - 22\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI KTP Mobile Panels V15 KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V15.1 Update 6), SIMATIC HMI KTP Mobile Panels V16 KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V16 Update 4), SIMATIC WinCC Runtime Advanced V15 (All versions < V15.1 Update 6), SIMATIC WinCC Runtime Advanced V16 (All versions < V16 Update 4). SmartVNC has an out-of-bounds memory access vulnerability that could be triggered on the server side when sending data from the client, which could result in a Denial-of-Service condition.
Affected
46 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | simatic_hmi_comfort_outdoor_panels_15_firmware | < 16 | 16 |
| siemens | simatic_hmi_comfort_outdoor_panels_15_firmware | < 15.1 | 15.1 |
| siemens | simatic_hmi_comfort_outdoor_panels_15_firmware | — | — |
| siemens | simatic_hmi_comfort_outdoor_panels_15_firmware | — | — |
| siemens | simatic_hmi_comfort_outdoor_panels_7_firmware | < 16 | 16 |
| siemens | simatic_hmi_comfort_outdoor_panels_7_firmware | < 15.1 | 15.1 |
| siemens | simatic_hmi_comfort_outdoor_panels_7_firmware | — | — |
| siemens | simatic_hmi_comfort_outdoor_panels_7_firmware | — | — |
| siemens | simatic_hmi_comfort_outdoor_panels_v15_7_15 | — | — |
| siemens | simatic_hmi_comfort_outdoor_panels_v16_7_15 | — | — |
| siemens | simatic_hmi_comfort_panels_22_firmware | < 16 | 16 |
| siemens | simatic_hmi_comfort_panels_22_firmware | < 15.1 | 15.1 |
| siemens | simatic_hmi_comfort_panels_22_firmware | — | — |
| siemens | simatic_hmi_comfort_panels_22_firmware | — | — |
| siemens | simatic_hmi_comfort_panels_4_firmware | < 16 | 16 |
| siemens | simatic_hmi_comfort_panels_4_firmware | < 15.1 | 15.1 |
| siemens | simatic_hmi_comfort_panels_4_firmware | — | — |
| siemens | simatic_hmi_comfort_panels_4_firmware | — | — |
| siemens | simatic_hmi_comfort_panels_v15_4_22 | — | — |
| siemens | simatic_hmi_comfort_panels_v16_4_22 | — | — |
| siemens | simatic_hmi_ktp_mobile_panels_ktp400f_firmware | < 16 | 16 |
| siemens | simatic_hmi_ktp_mobile_panels_ktp400f_firmware | < 15.1 | 15.1 |
| siemens | simatic_hmi_ktp_mobile_panels_ktp400f_firmware | — | — |
| siemens | simatic_hmi_ktp_mobile_panels_ktp400f_firmware | — | — |
| siemens | simatic_hmi_ktp_mobile_panels_ktp700_firmware | < 16 | 16 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Siemens SIMATIC HMI Comfort Outdoor Panels up to 16 Update 3 out-of-bounds write (ssa-538778)
vuldb·2026-06-03·CVSS 7.5
CVE-2021-25660 [HIGH] Siemens SIMATIC HMI Comfort Outdoor Panels up to 16 Update 3 out-of-bounds write (ssa-538778)
A vulnerability was found in Siemens SIMATIC HMI Comfort Outdoor Panels, SIMATIC HMI Comfort Panels, SIMATIC HMI KTP Mobile Panels and SIMATIC Wincc Runtime Advanced up to 16 Update 3. It has been declared as critical. Affected by this issue is some unknown functionality. The manipulation results in out-of-bounds write.
This vulnerability was named CVE-2021-25660. The attack needs to be approached within the local network. There is no available exploit.
A patch should be applied to remediate this issue.
GHSA
GHSA-rmq3-87p9-r2fp: A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels 7\" & 15\" (incl
ghsa_unreviewed·2022-05-24
CVE-2021-25660 [HIGH] CWE-119 GHSA-rmq3-87p9-r2fp: A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels 7\" & 15\" (incl
A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels 7\" & 15\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI Comfort Panels 4\" - 22\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V16 Update 4), SIMATIC WinCC Runtime Advanced (All versions < V16 Update 4). SmartVNC has an out-of-bounds memory access vulnerability that could be triggered on the server side when sending data from the client, which could result in a Denial-of-Service condition.
CISA ICS
Siemens SIMATIC SmartVNC HMI WinCC Products (Update B)
cisa_ics·2021-09-14
Siemens SIMATIC SmartVNC HMI WinCC Products (Update B)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SIMATIC SmartVNC HMI WinCC Products (Update B)
Last RevisedOctober 14, 2021
Alert CodeICSA-21-131-12
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely
- Vendor: Siemens
- Equipment: SIMATIC HMIs/WinCC Products
- Vulnerabilities: Access of Memory Location After End of Buffer, Improper Handling of Exceptional Conditions, Improper Restriction of Operations within the Bounds of a Memory Buffer, Uncontrolled Resource Consumption
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the original advisory titled ICSA-21-040-05 Siemens SIMA
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-05-12
Published