Post

Siemens WTV676 and WTV776 Vulnerability Advisory

Siemens WTV676 and WTV776 Vulnerability Advisory

Siemens WTV676 and WTV776 Vulnerability Advisory 🚨

The products Siemens WTV676 and WTV776 contain a denial of service vulnerability, identified as CVE-2026-89207. This vulnerability could allow an attacker to force the devices into protection mode under certain conditions, disabling remote connectivity functions (Web Access) to the devices.

Affected Versions:

  • WTV676-HB6035 Web Interface version: < 3.94
  • WTV776-HB6035 Web Interface version: < 4.17

Affected devices do not properly validate input received from backend services, allowing an unauthenticated remote attacker to force the device into protection mode, resulting in loss of remote connectivity functions. These products are deployed worldwide within Critical Infrastructure Sectors, specifically Energy.

Siemens has released new versions for the affected products and recommends updating to the latest versions:

  • For WTV676-HB6035 Web Interface, update to V3.94 or later.
  • For WTV776-HB6035 Web Interface, update to V4.17 or later.

As a general security measure, Siemens strongly recommends protecting network access to affected products with appropriate mechanisms and following recommended security practices to run devices in a protected IT environment. Additionally, CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities, including:

  • Minimizing network exposure for all control system devices and/or systems.
  • Ensuring they are not accessible from the internet.
  • Locating control system networks and remote devices behind firewalls, isolating them from business networks.
  • When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs).

CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.

For more information, see the associated Siemens security advisory SSA-823812.

Read full article

This post is licensed under CC BY 4.0 by the author.