ZeroHour

CVE-2021-25667

CVSS 3.1
8.8 high
EPSS
<1%p56
Published
()
Modified
Description

A vulnerability has been identified in RUGGEDCOM RM1224 (All versions >= V4.3 and = V4.3 and = V4.3 and = V2.0 and < V2.1.3), SCALANCE XB-200 (All versions < V4.1), SCALANCE XC-200 (All versions < V4.1), SCALANCE XF-200BA (All versions < V4.1), SCALANCE XM400 (All versions < V6.2), SCALANCE XP-200 (All versions < V4.1), SCALANCE XR-300WG (All versions < V4.1), SCALANCE XR500 (All versions < V6.2). Affected devices contain a stack-based buffer overflow vulnerability in the handling of STP BPDU frames that could allow a remote attacker to trigger a denial-of-service condition or potentially remote code execution. Successful exploitation requires the passive listening feature of the device to be active.

Vendors
siemens
Products
ruggedcom rm1224 firmware, scalance m-800 firmware, scalance s615 firmware, scalance x300wg firmware, scalance xm400 firmware, scalance xr500 firmware, scalance sc622-2c firmware, scalance sc632-2c firmware, scalance sc636-2c firmware, scalance sc642-2c firmware, scalance sc646-2c firmware, scalance xb-200 firmware
Weakness
CWE-121, CWE-787
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.