news.mlab.sh
Back to the feed
vulnerability

Siemens WTV676 and WTV776

MediumCVSS 6.5
Summary

A denial-of-service vulnerability exists in Siemens WTV676 and WTV776 devices, allowing an unauthenticated remote attacker to force the devices into protection mode, disabling remote connectivity. Siemens has released updates to address this issue. Organizations are urged to update their devices and minimize network exposure to control system devices.

Siemens has identified a denial-of-service vulnerability in its WTV676 and WTV776 devices. The vulnerability stems from a failure to properly validate input received from backend services, potentially enabling an unauthenticated remote attacker to force the device into protection mode. This action results in the loss of remote connectivity functions, specifically Web Access. Siemens has released updates to address this issue and recommends that users immediately update their devices to version V3.94 or later, or V4.17 or later, as detailed on the Siemens support website: [https://support.industry.siemens.com/cs/ww/en/view/109480838/](https://support.industry.siemens.com/cs/ww/en/view/109480838/).

To mitigate this risk, Siemens strongly recommends protecting network access to affected products with appropriate mechanisms and isolating control system networks and remote devices behind firewalls. When remote access is necessary, utilize more secure methods such as Virtual Private Networks (VPNs), recognizing that VPNs themselves may have vulnerabilities and should be kept up to date. Organizations are advised to perform thorough impact analysis and risk assessments before deploying defensive measures.

CISA recommends minimizing network exposure to control system devices and implementing cybersecurity strategies for proactive defense of ICS assets. This advisory is a verbatim republication of Siemens ProductCERT SSA-823812, converted to CISA's website for increased visibility and provided “as-is” for informational purposes only. Contact Siemens ProductCERT directly for any questions regarding this advisory.

Read the full article at CISA Advisories