mirror of
https://github.com/CVEProject/cvelist.git
synced 2025-07-29 05:56:59 +00:00
132 lines
6.4 KiB
JSON
132 lines
6.4 KiB
JSON
{
|
|
"CVE_data_meta": {
|
|
"ASSIGNER": "productcert@siemens.com",
|
|
"ID": "CVE-2021-25660",
|
|
"STATE": "PUBLIC"
|
|
},
|
|
"data_format": "MITRE",
|
|
"data_version": "4.0",
|
|
"data_type": "CVE",
|
|
"affects": {
|
|
"vendor": {
|
|
"vendor_data": [
|
|
{
|
|
"vendor_name": "Siemens",
|
|
"product": {
|
|
"product_data": [
|
|
{
|
|
"product_name": "SIMATIC HMI Comfort Outdoor Panels V15 7\\\" & 15\\\" (incl. SIPLUS variants)",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_value": "All versions < V15.1 Update 6"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "SIMATIC HMI Comfort Outdoor Panels V16 7\\\" & 15\\\" (incl. SIPLUS variants)\n",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_value": "All versions < V16 Update 4"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "SIMATIC HMI Comfort Panels V15 4\\\" - 22\\\" (incl. SIPLUS variants)",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_value": "All versions < V15.1 Update 6"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "SIMATIC HMI Comfort Panels V16 4\\\" - 22\\\" (incl. SIPLUS variants)\n",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_value": "All versions < V16 Update 4"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "SIMATIC HMI KTP Mobile Panels V15 KTP400F, KTP700, KTP700F, KTP900 and KTP900F",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_value": "All versions < V15.1 Update 6"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "SIMATIC HMI KTP Mobile Panels V16 KTP400F, KTP700, KTP700F, KTP900 and KTP900F\n",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_value": "All versions < V16 Update 4"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "SIMATIC WinCC Runtime Advanced V15",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_value": "All versions < V15.1 Update 6"
|
|
}
|
|
]
|
|
}
|
|
},
|
|
{
|
|
"product_name": "SIMATIC WinCC Runtime Advanced V16",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_value": "All versions < V16 Update 4"
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
}
|
|
},
|
|
"problemtype": {
|
|
"problemtype_data": [
|
|
{
|
|
"description": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "CWE-788: Access of Memory Location After End of Buffer"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
"description": {
|
|
"description_data": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\\\" & 15\\\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\\\" & 15\\\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI Comfort Panels V15 4\\\" - 22\\\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Panels V16 4\\\" - 22\\\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI KTP Mobile Panels V15 KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V15.1 Update 6), SIMATIC HMI KTP Mobile Panels V16 KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V16 Update 4), SIMATIC WinCC Runtime Advanced V15 (All versions < V15.1 Update 6), SIMATIC WinCC Runtime Advanced V16 (All versions < V16 Update 4). SmartVNC has an out-of-bounds memory access vulnerability that could be triggered on the server side when sending data from the client, which could result in a Denial-of-Service condition."
|
|
}
|
|
]
|
|
},
|
|
"references": {
|
|
"reference_data": [
|
|
{
|
|
"refsource": "MISC",
|
|
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-538778.pdf",
|
|
"name": "https://cert-portal.siemens.com/productcert/pdf/ssa-538778.pdf"
|
|
}
|
|
]
|
|
}
|
|
} |