Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-25667


A vulnerability has been identified in RUGGEDCOM RM1224 (All versions >= V4.3 and < V6.4), SCALANCE M-800 (All versions >= V4.3 and < V6.4), SCALANCE S615 (All versions >= V4.3 and < V6.4), SCALANCE SC-600 Family (All versions >= V2.0 and < V2.1.3), SCALANCE XB-200 (All versions < V4.1), SCALANCE XC-200 (All versions < V4.1), SCALANCE XF-200BA (All versions < V4.1), SCALANCE XM400 (All versions < V6.2), SCALANCE XP-200 (All versions < V4.1), SCALANCE XR-300WG (All versions < V4.1), SCALANCE XR500 (All versions < V6.2). Affected devices contain a stack-based buffer overflow vulnerability in the handling of STP BPDU frames that could allow a remote attacker to trigger a denial-of-service condition or potentially remote code execution. Successful exploitation requires the passive listening feature of the device to be active.


Published

2021-03-15T17:15:21.690

Last Modified

2024-11-21T05:55:15.360

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

CVSSv2 Vector

AV:A/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

6.5

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-121
  • Type: Secondary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System siemens ruggedcom_rm1224_firmware < 6.4 Yes
Hardware siemens ruggedcom_rm1224 - No
Operating System siemens scalance_m-800_firmware < 6.4 Yes
Hardware siemens scalance_m-800 - No
Operating System siemens scalance_s615_firmware < 6.4 Yes
Hardware siemens scalance_s615 - No
Operating System siemens scalance_x300wg_firmware < 4.1 Yes
Hardware siemens scalance_x300wg - No
Operating System siemens scalance_xm400_firmware < 6.2 Yes
Hardware siemens scalance_xm400 - No
Operating System siemens scalance_xr500_firmware < 6.2 Yes
Hardware siemens scalance_xr500 - No
Operating System siemens scalance_sc622-2c_firmware ≤ 2.0 Yes
Operating System siemens scalance_sc622-2c_firmware < 2.1.3 Yes
Hardware siemens scalance_sc622-2c - No
Operating System siemens scalance_sc632-2c_firmware ≤ 2.0 Yes
Operating System siemens scalance_sc632-2c_firmware < 2.1.3 Yes
Hardware siemens scalance_sc632-2c - No
Operating System siemens scalance_sc636-2c_firmware ≤ 2.0 Yes
Operating System siemens scalance_sc636-2c_firmware < 2.1.3 Yes
Hardware siemens scalance_sc636-2c - No
Operating System siemens scalance_sc642-2c_firmware ≤ 2.0 Yes
Operating System siemens scalance_sc642-2c_firmware < 2.1.3 Yes
Hardware siemens scalance_sc642-2c - No
Operating System siemens scalance_sc646-2c_firmware ≤ 2.0 Yes
Operating System siemens scalance_sc646-2c_firmware < 2.1.3 Yes
Hardware siemens scalance_sc646-2c - No
Operating System siemens scalance_xb-200_firmware < 4.1 Yes
Hardware siemens scalance_xb-200 - No
Operating System siemens scalance_xc-200_firmware < 4.1 Yes
Hardware siemens scalance_xc-200 - No
Operating System siemens scalance_xf-200ba_firmware < 4.1 Yes
Hardware siemens scalance_xf-200ba - No
Operating System siemens scalance_xp-200_firmware < 4.1 Yes
Hardware siemens scalance_xp-200 - No

References