CVE-2021-25667
Published Mar 15, 2021
Last updated 2 years ago
Overview
- Description
- A vulnerability has been identified in RUGGEDCOM RM1224 (All versions >= V4.3 and < V6.4), SCALANCE M-800 (All versions >= V4.3 and < V6.4), SCALANCE S615 (All versions >= V4.3 and < V6.4), SCALANCE SC-600 Family (All versions >= V2.0 and < V2.1.3), SCALANCE XB-200 (All versions < V4.1), SCALANCE XC-200 (All versions < V4.1), SCALANCE XF-200BA (All versions < V4.1), SCALANCE XM400 (All versions < V6.2), SCALANCE XP-200 (All versions < V4.1), SCALANCE XR-300WG (All versions < V4.1), SCALANCE XR500 (All versions < V6.2). Affected devices contain a stack-based buffer overflow vulnerability in the handling of STP BPDU frames that could allow a remote attacker to trigger a denial-of-service condition or potentially remote code execution. Successful exploitation requires the passive listening feature of the device to be active.
- Source
- productcert@siemens.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
CVSS 2.0
- Type
- Primary
- Base score
- 5.8
- Impact score
- 6.4
- Exploitability score
- 6.5
- Vector string
- AV:A/AC:L/Au:N/C:P/I:P/A:P
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:ruggedcom_rm1224_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0EA73ED4-CA84-4499-8B05-BA394552C91B", "versionEndExcluding": "6.4", "versionStartIncluding": "4.3" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:ruggedcom_rm1224:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "284DF779-D900-48B4-A177-7281CD445AB5" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_m-800_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "81E8F8B9-8CE5-45DD-8F66-00C2CD611158", "versionEndExcluding": "6.4", "versionStartIncluding": "4.3" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_m-800:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "DFB9921A-5204-40A3-88AB-B7755F5C6875" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_s615_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9E518F61-3BA5-4C49-B9F6-4F72333C6A59", "versionEndExcluding": "6.4", "versionStartIncluding": "4.3" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_s615:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "E917CBBB-EF41-4113-B0CA-EB91889235E7" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x300wg_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "147C2E5A-7085-4E63-8ED6-BDE56A6E333F", "versionEndExcluding": "4.1" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x300wg:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "AA0ECC58-F717-4F4A-AC8D-3F0244666E73" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_xm400_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "371C4BA0-42A9-4BA4-BE21-7C5D0F9E837B", "versionEndExcluding": "6.2" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_xm400:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "9FC408A8-903F-43A2-9D05-65AD4482FDBB" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_xr500_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "481EA136-48B6-46CA-8534-5F8F0E794F57", "versionEndExcluding": "6.2" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_xr500:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "080E722F-FCD4-4967-86EE-151ADC5702E7" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_sc622-2c_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "35E28605-DD44-42F2-9076-2ED1D6205043", "versionEndIncluding": "2.0" }, { "criteria": "cpe:2.3:o:siemens:scalance_sc622-2c_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "28F05973-CB28-46C2-BA62-654516FE7603", "versionEndExcluding": "2.1.3", "versionStartIncluding": "2.1" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_sc622-2c:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "50FEE5FA-B141-4E5F-8673-363089262530" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_sc632-2c_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CB080626-09C0-45CA-BE56-B3988E0E59C2", "versionEndIncluding": "2.0" }, { "criteria": "cpe:2.3:o:siemens:scalance_sc632-2c_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "08F55CDF-84A4-4356-B81A-F78F50B0CC1B", "versionEndExcluding": "2.1.3", "versionStartIncluding": "2.1" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_sc632-2c:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "8A79836B-5EC1-40AF-8A57-9657EF6758E5" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_sc636-2c_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D567B739-8271-4A43-9E1A-9FAF983DCBA1", "versionEndIncluding": "2.0" }, { "criteria": "cpe:2.3:o:siemens:scalance_sc636-2c_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DA160BE5-8790-4075-AE13-15569F9A5379", "versionEndExcluding": "2.1.3", "versionStartIncluding": "2.1" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_sc636-2c:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "FCB9BD17-7F1F-42E9-831F-EB907F9BC214" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_sc642-2c_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "23B81A14-B7A0-441E-998E-7F7B75088788", "versionEndIncluding": "2.0" }, { "criteria": "cpe:2.3:o:siemens:scalance_sc642-2c_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5323BADF-8F3F-4B0B-8875-6D2E4963B8CF", "versionEndExcluding": "2.1.3", "versionStartIncluding": "2.1" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_sc642-2c:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "10C7D54A-27B4-4195-8131-DD5380472A75" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_sc646-2c_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A90B1197-62AD-456C-99AF-8EC48461BDC5", "versionEndIncluding": "2.0" }, { "criteria": "cpe:2.3:o:siemens:scalance_sc646-2c_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CCD4C9CA-211C-4B1F-BDBD-C612DA76B0B2", "versionEndExcluding": "2.1.3", "versionStartIncluding": "2.1" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_sc646-2c:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "E54AF1E6-0E52-447C-8946-18716D30EBE2" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_xb-200_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "999A853F-1B20-4698-8391-805FE7055DF7", "versionEndExcluding": "4.1" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_xb-200:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "6CB3CC2D-CBF0-4F53-A412-01BBC39E34C2" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_xc-200_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C098F765-4BA2-4E59-9875-35FB5B83B6EB", "versionEndExcluding": "4.1" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_xc-200:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "7719E194-EE3D-4CE8-8C85-CF0D82A553AA" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_xf-200ba_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7CFE7041-F84D-40AE-9102-48637F000214", "versionEndExcluding": "4.1" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_xf-200ba:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "58377C58-F660-4C17-A3CB-BFC2F28848CD" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_xp-200_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5E81AEF3-1F99-4728-B3E1-FFBB22DA64E5", "versionEndExcluding": "4.1" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_xp-200:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "8F962FC7-0616-467F-8CCA-ADEA224B5F7B" } ], "operator": "OR" } ], "operator": "AND" } ]