Siemens SIMATIC, SIPLUS, and TIM
Multiple NULL pointer dereference vulnerabilities exist in the web server implementations of Siemens SIMATIC CP communication modules (versions before 3.5.20) and TIM 1531 IRC terminal modules (versions before 2.4.8), as well as in SIMATIC HMI Comfort Panels, SIMATIC IPC DiagBase, SIMATIC IPC DiagMonitor, and SIMATIC WinCC Runtime Advanced for which no patch is available. An attacker with network access to the webserver can trigger a NULL pointer dereference that crashes the webserver process, resulting in denial of service.
- Network access to the webserver port (typically 80/443)
- Webserver must be enabled on the device
- High attack complexity (non-trivial trigger conditions)
Patching may require device reboot — plan for process interruption
/api/v1/advisories/b923ad70-c065-456a-a8dc-f5702b37862dGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.