Vulnerability Change Records for CVE-2021-25662

Change History

CVE Modified by Siemens AG 9/14/2021 7:15:21 AM

Action Type Old Value New Value
Changed Description
SmartVNC client fails to handle an exception properly if the program execution process is modified after sending a packet from the server, which could result in a denial-of-service condition on the SIMATIC HMIs/WinCC Products SIMATIC HMI Comfort Outdoor Panels 7’ and 15’ (incl. SIPLUS variants), SIMATIC HMI Comfort Panels 4’to 22’ (incl. SIPLUS variants), SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900, and KTP900F, SIMATIC WinCC Runtime Advanced (All versions prior to v16 Update 4).
A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15 SP1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI Comfort Panels V15 4\" - 22\" (incl. SIPLUS variants) (All versions < V15 SP1 Update 6), SIMATIC HMI Comfort Panels V16 4\" - 22\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI KTP Mobile Panels V15 KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V15 SP1 Update 6), SIMATIC HMI KTP Mobile Panels V16 KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V16 Update 4), SIMATIC WinCC Runtime Advanced V15 (All versions < V15 SP1 Update 6), SIMATIC WinCC Runtime Advanced V16 (All versions < V16 Update 4). SmartVNC client fails to handle an exception properly if the program execution process is modified after sending a packet from the server, which could result in a Denial-of-Service condition.

Initial Analysis 5/21/2021 9:9:44 AM

Action Type Old Value New Value
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:siemens:simatic_hmi_comfort_outdoor_panels_15\"_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 16
          *cpe:2.3:o:siemens:simatic_hmi_comfort_outdoor_panels_15\"_firmware:16:-:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simatic_hmi_comfort_outdoor_panels_15\":-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:siemens:simatic_hmi_comfort_outdoor_panels_7\"_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 16
          *cpe:2.3:o:siemens:simatic_hmi_comfort_outdoor_panels_7\"_firmware:16:-:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simatic_hmi_comfort_outdoor_panels_7\":-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:siemens:simatic_hmi_comfort_panels_22\"_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 16
          *cpe:2.3:o:siemens:simatic_hmi_comfort_panels_22\"_firmware:16:-:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simatic_hmi_comfort_panels_22\":-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:siemens:simatic_hmi_comfort_panels_4\"_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 16
          *cpe:2.3:o:siemens:simatic_hmi_comfort_panels_4\"_firmware:16:-:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simatic_hmi_comfort_panels_4\":-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:siemens:simatic_hmi_ktp_mobile_panels_ktp400f_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 16
          *cpe:2.3:o:siemens:simatic_hmi_ktp_mobile_panels_ktp400f_firmware:16:-:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simatic_hmi_ktp_mobile_panels_ktp400f:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:siemens:simatic_hmi_ktp_mobile_panels_ktp700_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 16
          *cpe:2.3:o:siemens:simatic_hmi_ktp_mobile_panels_ktp700_firmware:16:-:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simatic_hmi_ktp_mobile_panels_ktp700:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:siemens:simatic_hmi_ktp_mobile_panels_ktp700f_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 16
          *cpe:2.3:o:siemens:simatic_hmi_ktp_mobile_panels_ktp700f_firmware:16:-:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simatic_hmi_ktp_mobile_panels_ktp700f:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:siemens:simatic_hmi_ktp_mobile_panels_ktp900_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 16
          *cpe:2.3:o:siemens:simatic_hmi_ktp_mobile_panels_ktp900_firmware:16:-:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simatic_hmi_ktp_mobile_panels_ktp900:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:siemens:simatic_hmi_ktp_mobile_panels_ktp900f_firmware:*:*:*:*:*:*:*:* versions up to (excluding) 16
          *cpe:2.3:o:siemens:simatic_hmi_ktp_mobile_panels_ktp900f_firmware:16:-:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:simatic_hmi_ktp_mobile_panels_ktp900f:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:a:siemens:simatic_wincc_runtime_advanced:*:*:*:*:*:*:*:* versions up to (excluding) 16
     *cpe:2.3:a:siemens:simatic_wincc_runtime_advanced:16:-:*:*:*:*:*:*
     *cpe:2.3:a:siemens:simatic_wincc_runtime_advanced:16:update1:*:*:*:*:*:*
     *cpe:2.3:a:siemens:simatic_wincc_runtime_advanced:16:update2:*:*:*:*:*:*
     *cpe:2.3:a:siemens:simatic_wincc_runtime_advanced:16:update3:*:*:*:*:*:*
Added CVSS V2

								
							
							
						
NIST (AV:N/AC:L/Au:N/C:N/I:N/A:P)
Added CVSS V3.1

								
							
							
						
NIST AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Changed Reference Type
https://cert-portal.siemens.com/productcert/pdf/ssa-538778.pdf No Types Assigned
https://cert-portal.siemens.com/productcert/pdf/ssa-538778.pdf Vendor Advisory
Changed Reference Type
https://us-cert.cisa.gov/ics/advisories/icsa-21-131-12 No Types Assigned
https://us-cert.cisa.gov/ics/advisories/icsa-21-131-12 Third Party Advisory, US Government Resource