CVE-2021-25668
Published Apr 22, 2021
Last updated 3 years ago
Overview
- Description
- A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < 5.5.1), SCALANCE X201-3P IRT (All versions < 5.5.1), SCALANCE X201-3P IRT PRO (All versions < 5.5.1), SCALANCE X202-2 IRT (All versions < 5.5.1), SCALANCE X202-2P IRT (incl. SIPLUS NET variant) (All versions < 5.5.1), SCALANCE X202-2P IRT PRO (All versions < 5.5.1), SCALANCE X204 IRT (All versions < 5.5.1), SCALANCE X204 IRT PRO (All versions < 5.5.1), SCALANCE X204-2 (incl. SIPLUS NET variant) (All versions < V5.2.5), SCALANCE X204-2FM (All versions < V5.2.5), SCALANCE X204-2LD (incl. SIPLUS NET variant) (All versions < V5.2.5), SCALANCE X204-2LD TS (All versions < V5.2.5), SCALANCE X204-2TS (All versions < V5.2.5), SCALANCE X206-1 (All versions < V5.2.5), SCALANCE X206-1LD (All versions < V5.2.5), SCALANCE X208 (incl. SIPLUS NET variant) (All versions < V5.2.5), SCALANCE X208PRO (All versions < V5.2.5), SCALANCE X212-2 (incl. SIPLUS NET variant) (All versions < V5.2.5), SCALANCE X212-2LD (All versions < V5.2.5), SCALANCE X216 (All versions < V5.2.5), SCALANCE X224 (All versions < V5.2.5), SCALANCE XF201-3P IRT (All versions < 5.5.1), SCALANCE XF202-2P IRT (All versions < 5.5.1), SCALANCE XF204 (All versions < V5.2.5), SCALANCE XF204 IRT (All versions < 5.5.1), SCALANCE XF204-2 (incl. SIPLUS NET variant) (All versions < V5.2.5), SCALANCE XF204-2BA IRT (All versions < 5.5.1), SCALANCE XF206-1 (All versions < V5.2.5), SCALANCE XF208 (All versions < V5.2.5). Incorrect processing of POST requests in the webserver may result in write out of bounds in heap. An attacker might leverage this to cause denial-of-service on the device and potentially remotely execute code.
- Source
- productcert@siemens.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
CVSS 2.0
- Type
- Primary
- Base score
- 7.5
- Impact score
- 6.4
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:P
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x200-4p_irt_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ADFA817F-7237-458A-8BCB-95551360E22A", "versionEndExcluding": "5.5.1" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x200-4p_irt:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "8B9CBC72-92D9-4B3A-884F-33124C457016" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x201-3p_irt_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "47627D33-BE10-42EC-AD9A-7E3FE4ECF6E2", "versionEndExcluding": "5.5.1" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x201-3p_irt:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "3268CF75-6DAB-416A-B19B-2A8F95C268CF" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x201-3p_irt_pro_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9328F7AC-5842-4525-9B30-7C8617063941", "versionEndExcluding": "5.5.1" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x201-3p_irt_pro:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "492E8AC1-338B-4AC3-90C7-1FADCD4528C4" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x202-2_irt_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "20883AFA-C61C-40DC-A343-3CDEA9B1B0AC", "versionEndExcluding": "5.5.1" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x202-2_irt:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "577D1E21-717C-4508-AE91-0BC490C89F85" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x202-2p_irt_pro_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AA284180-566E-45D5-B3B6-4617B89FF4B6", "versionEndExcluding": "5.5.1" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x202-2p_irt_pro:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "F4726901-34BF-4F70-80A6-71648A4A29FB" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x204_irt_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8A15A02F-7C41-4495-AD4E-11201FE5771F", "versionEndExcluding": "5.5.1" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x204_irt:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "0BC31F0E-389B-4925-88DE-726F2F0D2A23" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x204_irt_pro_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "40FCE8E4-B527-4B2D-AC98-C6649EAB4EC0", "versionEndExcluding": "5.5.1" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x204_irt_pro:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "8FF096BA-A6F4-46B3-9B9B-7FCEE7E6A6C3" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x204-2_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ACE1A821-8F0A-4B96-AC8A-B219215014B1", "versionEndExcluding": "5.2.5" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x204-2:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "E38CE5A4-3EB1-4E93-BEB7-520E08DA6720" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x204-2fm_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "54201E08-15E3-4C93-9A0D-DC376B7C8D88", "versionEndExcluding": "5.2.5" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x204-2fm:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "1FCBC784-8EA0-4C6C-B504-DFC164028E4B" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x204-2ld_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "75220631-DD7D-4E86-8405-F98340FFE27C", "versionEndExcluding": "5.2.5" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x204-2ld:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "2BE27611-53E7-4162-8630-5BC334B02E37" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x204-2ld_ts_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3032A499-DFD5-4FEA-8AC6-E661781387AB", "versionEndExcluding": "5.2.5" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x204-2ld_ts:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "1FDEBD6B-6BE4-4FAD-A4E6-BE762595434D" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x204-2ts_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A493C49A-8BF9-43E5-98D5-55E5390A36A5", "versionEndExcluding": "5.2.5" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x204-2ts:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "E5FFC1E9-4326-4F41-A86A-C52AB6A9A674" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x206-1_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E2C9747F-BEC3-486E-B553-3339F8B54C3A", "versionEndExcluding": "5.2.5" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x206-1:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "0A5BB0F2-DD4C-4AB4-9B8F-B2501B239080" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x206-1ld_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0C8D68AC-8F30-4919-ADB3-A6018458602B", "versionEndExcluding": "5.2.5" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x206-1ld:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "6DFF7FB7-774B-45ED-8400-951230DF0511" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x208_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2BC1450A-92ED-451F-9890-4E18CA974485", "versionEndExcluding": "5.2.5" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x208:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "B3B574E2-F7BA-496B-887C-D25F386AA5E1" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x208pro_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "768320F0-10F5-4B36-AEB6-9DEEA43A30E8", "versionEndExcluding": "5.2.5" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x208pro:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "DF2C60CF-4089-4993-A2CB-B7FBDAF81D62" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x212-2_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "31B8367C-5EAC-49F4-83B8-C7E3BD373092", "versionEndExcluding": "5.2.5" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x212-2:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "4E716A4E-50A9-4C52-8DA9-098F7506F4B5" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x212-2ld_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "55F50ABF-3E9A-4435-BAA4-7D11A2047D46", "versionEndExcluding": "5.2.5" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x212-2ld:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "C08CDEE3-43EB-475E-8571-6E12824714FD" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x216_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BC643617-D0B7-4379-8ADB-2C2BACA4B165", "versionEndExcluding": "5.2.5" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x216:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "F0C4BAB5-E161-4B59-8A8C-369C7852A66E" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x224_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F0189DF6-DA80-49FE-B09F-0C07D892518E", "versionEndExcluding": "5.2.5" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x224:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "D2203895-BC4E-4B2F-9110-C2CD88A121F2" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_xf201-3p_irt_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A73DE9A4-A86D-44BB-828F-F358D0E8102C", "versionEndExcluding": "5.5.1" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_xf201-3p_irt:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "41614C70-97B4-44C8-A441-530A413A26F9" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_xf202-2p_irt_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CA653B06-6B43-422B-9E51-4B29438841B4", "versionEndExcluding": "5.5.1" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_xf202-2p_irt:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "6751FB7D-C72C-4321-B535-5880FE696FC3" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_xf204_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8CD13707-1164-415E-9083-7946D151F1FC", "versionEndExcluding": "5.2.5" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_xf204:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "0F1AE867-67B4-4871-BF56-88017533A737" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_xf204_irt_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3FB90745-6B95-43A9-8211-DE32D1000827", "versionEndExcluding": "5.5.1" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_xf204_irt:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "25DDF1EB-80E7-491F-A197-1B220E35CDF1" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_xf204-2_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3A09FF2D-F369-47B5-AEE4-A862BEDD9851", "versionEndExcluding": "5.2.5" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_xf204-2:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "69285324-4C0B-4BDC-B60D-F653679DD52D" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_xf204-2ba_irt_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D634EE1A-2EB5-46FF-9E38-12DA3CDD3136", "versionEndExcluding": "5.5.1" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_xf204-2ba_irt:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "99E6AFAA-B903-47BB-B0F3-7650B039C0FB" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_xf206-1_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CFCDC84E-0695-409A-844B-D24024CC33F2", "versionEndExcluding": "5.2.5" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_xf206-1:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "2B40D2EB-5C69-47FA-801B-DC48407D418C" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_xf208_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A1DB6C03-71BF-4359-834B-384E78910E64", "versionEndExcluding": "5.2.5" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_xf208:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "898613B2-4A9D-44B9-A3FC-4347A2AD7CAB" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:siemens:scalance_x202-2p_irt_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2560F9B6-D121-4B82-A96F-81A0A4869616", "versionEndExcluding": "5.5.1" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:siemens:scalance_x202-2p_irt:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "CEB62730-E759-455A-A308-F9DB084B35B5" } ], "operator": "OR" } ], "operator": "AND" } ]