The vendor explicitly identifies these products as affected by this CVE.
- SIMATIC HMI Comfort Panels (incl. SIPLUS variants)
- SIMATIC HMI KTP Mobile Panels
- SIMATIC HMI KTP1200 Basic (6AV2123-2MB03-0AX0)
- SIMATIC HMI KTP400 Basic (6AV2123-2DB03-0AX0)
- SIMATIC HMI KTP700 Basic (6AV2123-2GB03-0AX0)
- SIMATIC HMI KTP900 Basic (6AV2123-2JB03-0AX0)
- SIPLUS HMI KTP1200 BASIC (6AG1123-2MB03-2AX0)
- SIPLUS HMI KTP400 BASIC (6AG1123-2DB03-2AX0)
- SIPLUS HMI KTP700 BASIC (6AG1123-2GB03-2AX0)
- SIPLUS HMI KTP900 BASIC (6AG1123-2JB03-2AX0)
- Summary
- Affected devices do not properly validate input sent to certain services over TCP. This could allow an unauthenticated remote attacker to cause a permanent denial of service condition (requiring a device reboot) by sending specially crafted TCP packets.
- Remediation
- Update to V17 Update 4 or later version
