60
CVE-2021-25677
—CVSS 3.1
5.3 medium
EPSS
1%p63
Published
()
Modified
Description
A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions = V0.5.0.0 < V1.0.0.0), TALON TC Compact (BACnet) (All versions < V3.5.5), TALON TC Modular (BACnet) (All versions < V3.5.5). The DNS client does not properly randomize DNS transaction IDs. That could allow an attacker to poison the DNS cache or spoof DNS resolving.
- Vendors
- siemens
- Products
- simotics connect 400 firmware, nucleus net, nucleus readystart v3, nucleus readystart v4, nucleus source code
- Weakness
- CWE-330
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N