CVE-2021-31344
—CVSS 4.0
6.9 medium
EPSS
1%p72
Published
()
Modified
Description
A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions), SIMOTICS CONNECT 400 (All versions < V0.5.0.0), SIMOTICS CONNECT 400 (All versions < V1.0.0.0). ICMP echo packets with fake IP options allow sending ICMP echo reply messages to arbitrary hosts on the network. (FSMD-2021-0004)
- Vendors
- siemens
- Products
- capital vstar, nucleus net, nucleus readystart v3, nucleus readystart v4, nucleus source code, apogee modular building controller firmware, apogee modular equiment controller firmware, apogee pxc compact firmware, apogee pxc modular firmware, talon tc compact firmware, talon tc modular firmware
- Weakness
- CWE-843
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.