CVE-2021-31889
—CVSS 3.1
9.1 critical
EPSS
2%p81
Published
()
Modified
Description
A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions), SIMOTICS CONNECT 400 (All versions < V0.5.0.0). Malformed TCP packets with a corrupted SACK option leads to Information Leaks and Denial-of-Service conditions. (FSMD-2021-0015)
- Vendors
- siemens
- Products
- capital vstar, nucleus net, nucleus readystart v3, nucleus source code, apogee modular building controller firmware, apogee modular equiment controller firmware, apogee pxc compact firmware, apogee pxc modular firmware, talon tc compact firmware, talon tc modular firmware
- Weakness
- CWE-191
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.