5.8
CVSSv2

CVE-2021-25667

Published: 15/03/2021 Updated: 19/10/2022
CVSS v2 Base Score: 5.8 | Impact Score: 6.4 | Exploitability Score: 6.5
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 516
Vector: AV:A/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A vulnerability has been identified in RUGGEDCOM RM1224 (All versions >= V4.3 and < V6.4), SCALANCE M-800 (All versions >= V4.3 and < V6.4), SCALANCE S615 (All versions >= V4.3 and < V6.4), SCALANCE SC-600 Family (All versions >= V2.0 and < V2.1.3), SCALANCE XB-200 (All versions < V4.1), SCALANCE XC-200 (All versions < V4.1), SCALANCE XF-200BA (All versions < V4.1), SCALANCE XM400 (All versions < V6.2), SCALANCE XP-200 (All versions < V4.1), SCALANCE XR-300WG (All versions < V4.1), SCALANCE XR500 (All versions < V6.2). Affected devices contain a stack-based buffer overflow vulnerability in the handling of STP BPDU frames that could allow a remote malicious user to trigger a denial-of-service condition or potentially remote code execution. Successful exploitation requires the passive listening feature of the device to be active.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

siemens ruggedcom_rm1224_firmware

siemens scalance_m-800_firmware

siemens scalance_s615_firmware

siemens scalance_x300wg_firmware

siemens scalance_xm400_firmware

siemens scalance_xr500_firmware

siemens scalance_sc622-2c_firmware

siemens scalance_sc632-2c_firmware

siemens scalance_sc636-2c_firmware

siemens scalance_sc642-2c_firmware

siemens scalance_sc646-2c_firmware

siemens scalance_xb-200_firmware

siemens scalance_xc-200_firmware

siemens scalance_xf-200ba_firmware

siemens scalance_xp-200_firmware