2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2021-25667" ,
"sourceIdentifier" : "productcert@siemens.com" ,
"published" : "2021-03-15T17:15:21.690" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-21T05:55:15.360" ,
"vulnStatus" : "Modified" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2023-04-24 12:24:31 +02:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "A vulnerability has been identified in RUGGEDCOM RM1224 (All versions >= V4.3 and < V6.4), SCALANCE M-800 (All versions >= V4.3 and < V6.4), SCALANCE S615 (All versions >= V4.3 and < V6.4), SCALANCE SC-600 Family (All versions >= V2.0 and < V2.1.3), SCALANCE XB-200 (All versions < V4.1), SCALANCE XC-200 (All versions < V4.1), SCALANCE XF-200BA (All versions < V4.1), SCALANCE XM400 (All versions < V6.2), SCALANCE XP-200 (All versions < V4.1), SCALANCE XR-300WG (All versions < V4.1), SCALANCE XR500 (All versions < V6.2). Affected devices contain a stack-based buffer overflow vulnerability in the handling of STP BPDU frames that could allow a remote attacker to trigger a denial-of-service condition or potentially remote code execution. Successful exploitation requires the passive listening feature of the device to be active."
} ,
{
"lang" : "es" ,
"value" : "Se ha identificado una vulnerabilidad en RUGGEDCOM RM1224 (Todas las versiones posteriores e incluyendo a V4.3 y anteriores a V6.4), SCALANCE M-800 (Todas las versiones posteriores e incluyendo a V4.3 y anteriores a V6.4), SCALANCE S615 (Todas las versiones posteriores e incluyendo a V4.3 y anteriores a V6.4), SCALANCE SC-600 Family (Todas las versiones posteriores e incluyendo a V2.0 y anteriores a V2.1.3), SCALANCE XB-200 (Todas las versiones anteriores a V4.1), SCALANCE XC-200 (Todas las versiones anteriores a V4.1), SCALANCE XF-200BA (Todas las versiones anteriores a V4.1), SCALANCE XM400 (Todas las versiones anteriores a V6.2), SCALANCE XP-200 (Todas las versiones anteriores a V4.1), SCALANCE XR-300WG (Todas las versiones anteriores a V4.1), SCALANCE XR500 (Todas las versiones anteriores a V6.2). Unos dispositivos afectados contienen una vulnerabilidad de desbordamiento de b\u00fafer en la regi\u00f3n stack de la memoria en el manejo de frames STP BPDU que podr\u00eda permitir a un atacante remoto desencadenar una condici\u00f3n de denegaci\u00f3n de servicio o una ejecuci\u00f3n de c\u00f3digo potencialmente remoto. Una explotaci\u00f3n con \u00e9xito requiere que la funcionalidad listening pasiva del dispositivo est\u00e9 activa"
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 8.8 ,
"baseSeverity" : "HIGH" ,
2023-04-24 12:24:31 +02:00
"attackVector" : "ADJACENT_NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "HIGH"
2023-04-24 12:24:31 +02:00
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 5.9
}
] ,
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:A/AC:L/Au:N/C:P/I:P/A:P" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 5.8 ,
2023-04-24 12:24:31 +02:00
"accessVector" : "ADJACENT_NETWORK" ,
"accessComplexity" : "LOW" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "PARTIAL" ,
"integrityImpact" : "PARTIAL" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "PARTIAL"
2023-04-24 12:24:31 +02:00
} ,
"baseSeverity" : "MEDIUM" ,
"exploitabilityScore" : 6.5 ,
"impactScore" : 6.4 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : false
}
]
} ,
"weaknesses" : [
{
"source" : "productcert@siemens.com" ,
2024-12-15 03:03:56 +00:00
"type" : "Primary" ,
2023-04-24 12:24:31 +02:00
"description" : [
{
"lang" : "en" ,
"value" : "CWE-121"
}
]
} ,
{
"source" : "nvd@nist.gov" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-787"
}
]
}
] ,
"configurations" : [
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:ruggedcom_rm1224_firmware:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "4.3" ,
"versionEndExcluding" : "6.4" ,
"matchCriteriaId" : "0EA73ED4-CA84-4499-8B05-BA394552C91B"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:ruggedcom_rm1224:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "284DF779-D900-48B4-A177-7281CD445AB5"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:scalance_m-800_firmware:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "4.3" ,
"versionEndExcluding" : "6.4" ,
"matchCriteriaId" : "81E8F8B9-8CE5-45DD-8F66-00C2CD611158"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:scalance_m-800:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "DFB9921A-5204-40A3-88AB-B7755F5C6875"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:scalance_s615_firmware:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "4.3" ,
"versionEndExcluding" : "6.4" ,
"matchCriteriaId" : "9E518F61-3BA5-4C49-B9F6-4F72333C6A59"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:scalance_s615:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E917CBBB-EF41-4113-B0CA-EB91889235E7"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:scalance_x300wg_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "4.1" ,
"matchCriteriaId" : "147C2E5A-7085-4E63-8ED6-BDE56A6E333F"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:scalance_x300wg:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "AA0ECC58-F717-4F4A-AC8D-3F0244666E73"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:scalance_xm400_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "6.2" ,
"matchCriteriaId" : "371C4BA0-42A9-4BA4-BE21-7C5D0F9E837B"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:scalance_xm400:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9FC408A8-903F-43A2-9D05-65AD4482FDBB"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:scalance_xr500_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "6.2" ,
"matchCriteriaId" : "481EA136-48B6-46CA-8534-5F8F0E794F57"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:scalance_xr500:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "080E722F-FCD4-4967-86EE-151ADC5702E7"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:scalance_sc622-2c_firmware:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "2.0" ,
"matchCriteriaId" : "35E28605-DD44-42F2-9076-2ED1D6205043"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:scalance_sc622-2c_firmware:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "2.1" ,
"versionEndExcluding" : "2.1.3" ,
"matchCriteriaId" : "28F05973-CB28-46C2-BA62-654516FE7603"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:scalance_sc622-2c:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "50FEE5FA-B141-4E5F-8673-363089262530"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:scalance_sc632-2c_firmware:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "2.0" ,
"matchCriteriaId" : "CB080626-09C0-45CA-BE56-B3988E0E59C2"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:scalance_sc632-2c_firmware:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "2.1" ,
"versionEndExcluding" : "2.1.3" ,
"matchCriteriaId" : "08F55CDF-84A4-4356-B81A-F78F50B0CC1B"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:scalance_sc632-2c:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8A79836B-5EC1-40AF-8A57-9657EF6758E5"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:scalance_sc636-2c_firmware:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "2.0" ,
"matchCriteriaId" : "D567B739-8271-4A43-9E1A-9FAF983DCBA1"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:scalance_sc636-2c_firmware:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "2.1" ,
"versionEndExcluding" : "2.1.3" ,
"matchCriteriaId" : "DA160BE5-8790-4075-AE13-15569F9A5379"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:scalance_sc636-2c:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "FCB9BD17-7F1F-42E9-831F-EB907F9BC214"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:scalance_sc642-2c_firmware:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "2.0" ,
"matchCriteriaId" : "23B81A14-B7A0-441E-998E-7F7B75088788"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:scalance_sc642-2c_firmware:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "2.1" ,
"versionEndExcluding" : "2.1.3" ,
"matchCriteriaId" : "5323BADF-8F3F-4B0B-8875-6D2E4963B8CF"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:scalance_sc642-2c:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "10C7D54A-27B4-4195-8131-DD5380472A75"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:scalance_sc646-2c_firmware:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "2.0" ,
"matchCriteriaId" : "A90B1197-62AD-456C-99AF-8EC48461BDC5"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:scalance_sc646-2c_firmware:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "2.1" ,
"versionEndExcluding" : "2.1.3" ,
"matchCriteriaId" : "CCD4C9CA-211C-4B1F-BDBD-C612DA76B0B2"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:scalance_sc646-2c:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E54AF1E6-0E52-447C-8946-18716D30EBE2"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:scalance_xb-200_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "4.1" ,
"matchCriteriaId" : "999A853F-1B20-4698-8391-805FE7055DF7"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:scalance_xb-200:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "6CB3CC2D-CBF0-4F53-A412-01BBC39E34C2"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:scalance_xc-200_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "4.1" ,
"matchCriteriaId" : "C098F765-4BA2-4E59-9875-35FB5B83B6EB"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:scalance_xc-200:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "7719E194-EE3D-4CE8-8C85-CF0D82A553AA"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:scalance_xf-200ba_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "4.1" ,
"matchCriteriaId" : "7CFE7041-F84D-40AE-9102-48637F000214"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:scalance_xf-200ba:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "58377C58-F660-4C17-A3CB-BFC2F28848CD"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:scalance_xp-200_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "4.1" ,
"matchCriteriaId" : "5E81AEF3-1F99-4728-B3E1-FFBB22DA64E5"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:scalance_xp-200:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "8F962FC7-0616-467F-8CCA-ADEA224B5F7B"
}
]
}
]
}
] ,
"references" : [
{
"url" : "https://cert-portal.siemens.com/productcert/pdf/ssa-979775.pdf" ,
"source" : "productcert@siemens.com" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
} ,
{
"url" : "https://us-cert.cisa.gov/ics/advisories/icsa-21-068-03" ,
"source" : "productcert@siemens.com" ,
"tags" : [
"Patch" ,
"Third Party Advisory" ,
"US Government Resource"
]
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://cert-portal.siemens.com/productcert/pdf/ssa-979775.pdf" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch" ,
"Vendor Advisory"
]
} ,
{
"url" : "https://us-cert.cisa.gov/ics/advisories/icsa-21-068-03" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108" ,
"tags" : [
"Patch" ,
"Third Party Advisory" ,
"US Government Resource"
]
2023-04-24 12:24:31 +02:00
}
]
}