← Vulnerability feed

Vulnerability record · CVE-2018-13814 · published 13 December 2018

CVE-2018-13814: Siemens simatic hmi comfort panels firmware improper input validation vulnerability

Siemens · Simatic Hmi Comfort Panels Firmware

A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V14), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (All versions < V14), SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V14), SIMATIC WinCC Runtime Advanced (All versions < V14), SIMATIC WinCC Runtime Professional (All versions < V14), SIMATIC WinCC (TIA Portal) (All versions < V14), SIMATIC HMI Classic Devices (TP/MP/OP/MP Mobile Panel) (All versions). The integrated web server (port 80/tcp and port 443/tcp) of the affected devices could allow an attacker to inject HTTP headers. An attacker must trick a valid user who is authenticated to the device into clicking on a malicious link to exploit the vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

8.8 CVSS 3.0 High EPSS 1.7% · top 23.9% CWE-113 · CWE-113CWE-20 · Improper input validation
8.8CVSS 3.0 base score, v2 6.8
1.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
12Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V14), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (All versions < V14), SIMATIC HMI KTP Mobile Panels KTP400F, KTP700, KTP700F, KTP900 and KTP900F (All versions < V14), SIMATIC WinCC Runtime Advanced (All versions < V14), SIMATIC WinCC Runtime Professional (All versions < V14), SIMATIC WinCC (TIA Portal) (All versions < V14), SIMATIC HMI Classic Devices (TP/MP/OP/MP Mobile Panel) (All versions). The integrated web server (port 80/tcp and port 443/tcp) of the affected devices could allow an attacker to inject HTTP headers. An attacker must trick a valid user who is authenticated to the device into clicking on a malicious link to exploit the vulnerability. At the time of advisory publication no public exploitation of this security vulnerability was known.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

12 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-13814 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-27384Siemens simatic wincc runtime advanced vulnerabilityA vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIM…EPSS 2.6%9.8CVE-2020-15798Siemens simatic hmi comfort panels firmware missing authentication for critical function vulnerabilityA vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V16 Update 3a), SIMATIC HMI KTP Mobile Pane…EPSS 5.2%9.8CVE-2020-15786Siemens simatic hmi basic panels 2nd generation firmware improper restriction of authentication attempts vulnerabilityA vulnerability has been identified in SIMATIC HMI Basic Panels 2nd Generation (incl. SIPLUS variants) (All versions < V16), SIMATIC HMI Comfort Pane…EPSS 1.5%9.1CVE-2019-6572Siemens simatic hmi comfort panels firmware information exposure vulnerabilityA vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15.1 Update 1), SIMATIC HMI Comfort Outdoor Panels 7" & 1…EPSS 2.7%8.1CVE-2018-13813Siemens simatic hmi comfort panels firmware open redirect vulnerabilityA vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15 Update 4), SIMATIC HMI Comfort Outdoor Panels 7" & 15"…EPSS 1.7%7.5CVE-2022-40227Siemens simatic hmi comfort panels firmware improper input validation vulnerabilityA vulnerability has been identified in SIMATIC HMI Comfort Panels (incl. SIPLUS variants) (All versions < V17 Update 4), SIMATIC HMI KTP Mobile Panel…EPSS 0.84%7.5CVE-2021-25660Siemens simatic hmi comfort outdoor panels 7\" firmware memory buffer overflow vulnerabilityA vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIM…EPSS 0.97%7.5CVE-2021-25661Siemens simatic wincc runtime advanced vulnerabilityA vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIM…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2018-13814), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.