CVE-2021-25659 PUBLISHED CVSS 7.5 HIGH

A vulnerability has been identified in Automation License Manager 5 (All versions), Automation License Manager 6 (All versions < V6.0 SP9 Update 2). Sending specially crafted packets to port 4410/tcp of an affected system could lead to extensive memory being consumed and as such could cause a denial-of-service preventing legitimate users from using the system.

EPSS 0.44% · 63.2th percentile

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.44%
63.2th percentile

Affected Products

VendorProductVersions
SiemensAutomation License Manager 5All versions
SiemensAutomation License Manager 6All versions < V6.0 SP9 Update 2
siemensautomation_license_manager5.0.0

Timeline

References

Open in Interactive Console →