CVE-2019-19276: Medium severity siemens simatic hmi ktp mobile panels firmware vulnerability
A vulnerability has been identified in SIMATIC HMI Comfort Panels 1st Generation (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI KTP Mobile Panels (All versions < V16 Update 4). Specially crafted packets sent to port 161/udp can cause the SNMP service of affected devices to crash. A manual restart of the device is required to resume operation of the service.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-19276?
The severity of CVE-2019-19276 is medium with a severity value of 5.3.
Which software versions are affected by CVE-2019-19276?
SIMATIC HMI Comfort Panels 1st Generation (incl. SIPLUS variants) versions < V16 Update 4 and SIMATIC HMI KTP Mobile Panels versions < V16 Update 4 are affected by CVE-2019-19276.
How does CVE-2019-19276 vulnerability occur?
The vulnerability occurs when specially crafted packets are sent to port 161/udp, causing the SNMP service of affected devices to crash.
Is IBM Security Verify Access affected by CVE-2019-19276?
No, IBM Security Verify Access is not affected by CVE-2019-19276.
How can I fix CVE-2019-19276?
Update the SIMATIC HMI Comfort Panels 1st Generation (incl. SIPLUS variants) and SIMATIC HMI KTP Mobile Panels firmware to V16 Update 4 or later to mitigate the vulnerability.