IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Siemens WTV676 and WTV776

MEDIUM
CVSS 6.5
Date 2026-09-22T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

The products listed below contain a denial of service vulnerability that could allow an attacker to force the devices into protection mode under certain conditions. This disables remote connectivity functions (Web Access) to the devices. Siemens has released new versions for the affected products and recommends to update to the latest versions.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-89207 6.5 medium
CVE-2026-89207. Affected devices do not properly validate input received from backend services. This could allow an unauthenticated remote attacker to force the device into protection mode, which results in losing remote connectivity functions (Web Access).

// Remediations (4)

Patch: Update to V4.17 or later version
Update to V4.17 or later version
Patch: Update to V3.94 or later version
Update to V3.94 or later version
Patch: Update to V4.17 or later version
Update to V4.17 or later version
Patch: Update to V3.94 or later version
Update to V3.94 or later version

// References