QID 590743

QID 590743: Siemens SNMP Implementation of WinCC Runtime Vulnerability (ICSA-21-131-06)

AFFECTED PRODUCTS
The following products are affected due to the SNMP implementation of WinCC Runtime:
SIMATIC HMI Comfort Panels 1st Generation (incl. SIPLUS variants): All versions prior to v16 update 4
SIMATIC HMI KTP Mobile Panels: All versions prior to v16 update 4

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of this vulnerability could crash the SNMP service and require a manual restart of the device to resume operation of the service.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-21-131-06 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590743

    Software Advisories
    Advisory ID Software Component Link
    ICSA-21-131-06 URL Logo www.us-cert.gov/ics/advisories/ICSA-21-131-06