Full Report
The products listed below contain a denial of service vulnerability that could allow an attacker to force the devices into protection mode under certain conditions. This disables remote connectivity functions (Web Access) to the devices. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Analysis Summary
# Vulnerability: Denial of Service in Siemens WTV676 and WTV776 Web Interfaces
## CVE Details
- **CVE ID:** CVE-2026-89207
- **CVSS Score:**
- CVSS v3.1: 6.5 (Medium)
- CVSS v4.0: 6.9 (Medium)
- **CWE:** CWE-1287 (Improper Validation of Specified Type of Input)
## Affected Systems
- **Products:**
- WTV676-HB6035 Web Interface
- WTV776-HB6035 Web Interface
- **Versions:**
- WTV676: All versions prior to V3.94
- WTV776: All versions prior to V4.17
- **Configurations:** Devices utilizing remote connectivity functions (Web Access).
## Vulnerability Description
The affected devices fail to properly validate input received from backend services. A remote, unauthenticated attacker can exploit this flaw by sending specific input that triggers a "protection mode" state. Once in protection mode, the device disables its remote connectivity functions (Web Access), resulting in a Denial of Service (DoS) for management operations.
## Exploitation
- **Status:** Not exploited (No reports of active exploitation in the wild or public PoC provided in advisory).
- **Complexity:** Low
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** None
- **Integrity:** Low (Persistence of the "protection mode" state)
- **Availability:** Low (Specific to Web Access/remote connectivity functions)
## Remediation
### Patches
Siemens recommends updating to the following versions:
- **WTV676-HB6035:** Update to **V3.94** or later.
- **WTV776-HB6035:** Update to **V4.17** or later.
### Workarounds
- **Network Segmentation:** Protect network access to affected products using appropriate mechanisms (e.g., firewalls, VLANs).
- **Operational Security:** Ensure devices are operated only within protected IT environments following general security best practices.
## Detection
- **Indicators of Compromise:** Sudden loss of Web Interface accessibility while other hardware functions may remain operational; device logs indicating entry into "protection mode."
- **Detection methods and tools:** Network monitoring for unexpected traffic patterns targeting backend communication ports; periodic health checks of the Web Access interface.
## References
- **Vendor Advisory:** hxxps://cert-portal.siemens[.]com/productcert/html/ssa-823812.html
- **Software Downloads:** hxxps://support.industry.siemens[.]com/cs/ww/en/view/109480838/
- **Siemens ProductCERT:** hxxps://www.siemens[.]com/cert/advisories