Impact
An identified weakness in Siemens" WTV676-HB6035 and WTV776-HB6035 Web Interfaces allows an attacker without credentials to exploit improper input handling from backend services. By sending crafted input, an attacker can force the device into protection mode, which terminates its remote connectivity features, specifically disabling web access. This results in a denial of web‑based management functionality and does not, as currently described, provide access to sensitive data or system control beyond service disruption.
Affected Systems
The flaw is present in all versions of the WTV676-HB6035 Web Interface earlier than V3.94 and in all versions of the WTV776-HB6035 Web Interface before V4.17. Siemens customers using these older firmware releases are impacted.
Risk and Exploitability
The CVSS base score of 6.9 indicates moderate severity, and the EPSS score below 1% suggests exploitation is unlikely but possible. Because the attack does not require authentication and can be performed remotely through the interface that communicates with backend services, the attack surface is relatively open, although the vulnerability is not listed in the CISA KEV catalog. The primary risk is loss of remote management capability rather than data compromise.
OpenCVE Enrichment