Our takeSiemens fixed a DoS in the WTV676 and WTV776 that forces the units into protection mode and kills remote web access. Update to the latest firmware.Cyber Resilience desk
Sources (1)
- cisa_advisories · cisa_advisories
What this means for you — Security leader:Update Siemens WTV676 and WTV776 to the latest firmware versions to prevent a DoS that forces devices into protection mode and disables remote Web Access.
What this means for you — Lean IT orgs:If you use Siemens WTV676 or WTV776 heating controllers, apply the manufacturer’s latest firmware update as soon as you can; the flaw lets an attacker knock out remote access until the unit is power-cycled.
What this means for you — MSP:Audit client environments for Siemens WTV676 and WTV776 deployments (commonly found in building automation and district heating); schedule immediate firmware updates on affected units to close the DoS vector that disables remote connectivity.
What this means for you — Researcher:Review the updated firmware and protection-mode logic in Siemens WTV676/WTV776; the conditions that trigger the DoS deserve closer analysis for similar edge cases in other OT heating controllers.