ZeroHour

CVE-2021-31881

CVSS 3.1
7.5 high
EPSS
2%p73
Published
()
Modified
Description

A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303). When processing a DHCP OFFER message, the DHCP client application does not validate the length of the Vendor option(s), leading to Denial-of-Service conditions. (FSMD-2021-0008)

Vendors
siemens
Products
capital vstar, nucleus net, nucleus readystart v3, nucleus source code, apogee modular building controller firmware, apogee modular equiment controller firmware, apogee pxc compact firmware, apogee pxc modular firmware, talon tc compact firmware, talon tc modular firmware
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.