The vendor explicitly identifies these products as affected by this CVE.
- SIMATIC HMI Comfort Outdoor Panels 7" & 15" (incl. SIPLUS variants)
- SIMATIC HMI Comfort Panels 4" - 22" (incl. SIPLUS variants)
- SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 and KTP900F
- SIMATIC ITC1500 V3.1
- SIMATIC ITC1500 V3.1 PRO
- SIMATIC ITC1900 V3.1
- SIMATIC ITC1900 V3.1 PRO
- SIMATIC ITC2200 V3.1
- SIMATIC ITC2200 V3.1 PRO
- SIMATIC WinCC Runtime Advanced
- SIMATIC WinCC Runtime Professional
- Summary
- TightVNC code version 1.3.10 contains null pointer dereference in HandleZlibBPP function, which could result in a Denial-of-Service (DoS). This attack appear to be exploitable via network connectivity.
- Remediation
- This product is not affected by any vulnerability listed in this advisory
