CVE Vulnerabilities

CVE-2021-25661

Access of Memory Location After End of Buffer

Published: May 12, 2021 | Modified: Dec 16, 2021
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7 & 15 (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7 & 15 (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI Comfort Panels V15 4 - 22 (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Panels V16 4 - 22 (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI KTP Mobile Panels V15 KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V15.1 Update 6), SIMATIC HMI KTP Mobile Panels V16 KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V16 Update 4), SIMATIC WinCC Runtime Advanced V15 (All versions < V15.1 Update 6), SIMATIC WinCC Runtime Advanced V16 (All versions < V16 Update 4). SmartVNC has an out-of-bounds memory access vulnerability that could be triggered on the client side when sending data from the server, which could result in a Denial-of-Service condition.

Weakness

The product reads or writes to a buffer using an index or pointer that references a memory location after the end of the buffer.

Affected Software

Name Vendor Start Version End Version
Simatic_wincc_runtime_advanced Siemens * 16 (excluding)
Simatic_wincc_runtime_advanced Siemens 16 (including) 16 (including)
Simatic_wincc_runtime_advanced Siemens 16-update1 (including) 16-update1 (including)
Simatic_wincc_runtime_advanced Siemens 16-update2 (including) 16-update2 (including)
Simatic_wincc_runtime_advanced Siemens 16-update3 (including) 16-update3 (including)

References