ICSA-21-131-11: Siemens SIMATIC UltraVNC HMI WinCC Products
CISA advisory · released 2021-05-11
Source record Collected from CISA's CSAF advisory feed
- Distribution label in the document: TLP:WHITE
- Revision 2, 2025-05-06 (final)
CISA's summary
Summary: UltraVNC vulnerabilities in the affected products listed below could allow remote code execution, information disclosure and Denial-of-Service attacks under certain conditions. Siemens has released updates for the affected products and recommends to update to the latest versions.
Products, as the advisory lists them
| Vendor | Product | Version |
|---|---|---|
| Siemens | SIMATIC HMI Comfort Outdoor Panels 7" & 15" (incl. SIPLUS variants) | <V16_Update_4 |
| Siemens | SIMATIC HMI Comfort Panels 4" - 22" (incl. SIPLUS variants) | <V16_Update_4 |
| Siemens | SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 and KTP900F | <V16_Update_4 |
| Siemens | SIMATIC WinCC Runtime Advanced | <V16_Update_4 |
DeSpy has not checked any unit, hardware revision or firmware.
Vulnerabilities in this advisory
- CVE-2019-8259 — CVE-2019-8259 · CWE-665
UltraVNC revision 1198 contains multiple memory leaks in VNC client code, which could allow an attacker to read stack memory and can be abused for information disclosure. Combined with another vulnerability, it can be used to leak stack memory and bypass ASLR. This vulnerability appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1199.
- CVE-2019-8260 — CVE-2019-8260 · CWE-125
UltraVNC revision 1199 has a out-of-bounds read vulnerability in VNC client RRE decoder code, caused by multiplication overflow. This vulnerability appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1200.
- CVE-2019-8261 — CVE-2019-8261 · CWE-125
UltraVNC revision 1199 has a out-of-bounds read vulnerability in VNC code inside client CoRRE decoder, caused by multiplication overflow. This vulnerability appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1200.
- CVE-2019-8262 — CVE-2019-8262 · CWE-122
UltraVNC revision 1203 has multiple heap buffer overflow vulnerabilities in VNC client code inside Ultra decoder, which could result in code execution. This vulnerability appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1204.
- CVE-2019-8263 — CVE-2019-8263 · CWE-121
UltraVNC revision 1205 has a stack-based buffer overflow vulnerability in VNC client code inside ShowConnInfo routine, which could lead to a denial of service (DoS) condition. This vulnerability appear to be exploitable via network connectivity. User interaction is required to trigger this vulnerability. This vulnerability has been fixed in revision 1206.
- CVE-2019-8264 — CVE-2019-8264 · CWE-788
UltraVNC revision 1203 has a out-of-bounds access vulnerability in VNC client inside Ultra2 decoder, which can potentially result in code execution. This vulnerability appears to be exploitable via network connectivity. This vulnerability has been fixed in revision 1204.
- CVE-2019-8265 — CVE-2019-8265 · CWE-788
UltraVNC revision 1207 has multiple out-of-bounds access vulnerabilities connected with improper usage of SETPIXELS macro in VNC client code, which can potentially result in code execution. This vulnerability appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1208.
- CVE-2019-8275 — CVE-2019-8275 · CWE-170
UltraVNC revision 1211 has multiple improper null termination vulnerabilities in VNC server code, which could result in out-of-bound data being accessed by remote users. This vulnerability appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1212.
- CVE-2019-8277 — CVE-2019-8277 · CWE-665
UltraVNC revision 1211 contains multiple memory leaks in VNC server code, which could allow an attacker to read stack memory and can be abused for information disclosure. Combined with another vulnerability, it can be used to leak stack memory and bypass ASLR. This vulnerability appears to be exploitable via network connectivity. These vulnerabilities have been fixed in revision 1212.
- CVE-2019-8280 — CVE-2019-8280 · CWE-788
UltraVNC revision 1203 has out-of-bounds access vulnerability in VNC client inside RAW decoder, which can potentially result in code execution. This vulnerability appear to be exploitable via network connectivity. This vulnerability has been fixed in revision 1204.
Acknowledgments, as the advisory lists them
- Siemens ProductCERT: reporting these vulnerabilities to CISA.
The advisory's legal notice
Siemens Security Advisories are subject to the terms and conditions contained in Siemens' underlying license terms or other applicable agreements previously agreed to with Siemens (hereinafter "License Terms"). To the extent applicable to information, software or documentation made available in or through a Siemens Security Advisory, the Terms of Use of Siemens' Global Website (https://www.siemens.com/terms_of_use, hereinafter "Terms of Use"), in particular Sections 8-10 of the Terms of Use, shall apply additionally. In case of conflicts, the License Terms shall prevail over the Terms of Use.
Sources
DeSpy's copy of this version is dated 2026-09-28.
This product uses the NVD API but is not endorsed or certified by the NVD.
CVE records: Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation.
CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE™). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.
CISA's Known Exploited Vulnerabilities catalog and CISA Vulnrichment data are CC0 1.0. CISA advisories are shown with the TLP label their document carries. No endorsement by CISA, DHS, NIST or MITRE is stated or implied.