CVE-2021-25668
A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < 5.5.1), SCALANCE X201-3P IRT (All versions < 5.5.1), SCALANCE X201-3P IRT PRO (All versions < 5.5.1), SCALANCE X202-2 IRT (All versions < 5.5.1), SCALANCE X202-2P IRT (incl. SIPLUS NET variant) (All versions < 5.5.1), SCALANCE X202-2P IRT PRO (All versions < 5.5.1), SCALANCE X204 IRT (All versions < 5.5.1), SCALANCE X204 IRT PRO (All versions < 5.5.1), SCALANCE X204-2 (incl. SIPLUS NET variant) (All versions), SCALANCE X204-2FM (All versions), SCALANCE X204-2LD (incl. SIPLUS NET variant) (All versions), SCALANCE X204-2LD TS (All versions), SCALANCE X204-2TS (All versions), SCALANCE X206-1 (All versions), SCALANCE X206-1LD (All versions), SCALANCE X208 (incl. SIPLUS NET variant) (All versions), SCALANCE X208PRO (All versions), SCALANCE X212-2 (incl. SIPLUS NET variant) (All versions), SCALANCE X212-2LD (All versions), SCALANCE X216 (All versions), SCALANCE X224 (All versions), SCALANCE XF201-3P IRT (All versions < 5.5.1), SCALANCE XF202-2P IRT (All versions < 5.5.1), SCALANCE XF204 (All versions), SCALANCE XF204 IRT (All versions < 5.5.1), SCALANCE XF204-2 (incl. SIPLUS NET variant) (All versions), SCALANCE XF204-2BA IRT (All versions < 5.5.1), SCALANCE XF206-1 (All versions), SCALANCE XF208 (All versions). Incorrect processing of POST requests in the webserver may result in write out of bounds in heap. An attacker might leverage this to cause denial-of-service on the device and potentially remotely execute code.
EPSS 1.28% · 79.9th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | SCALANCE X202-2 IRT | All versions < 5.5.1 |
| Siemens | SCALANCE XF204 | All versions < V5.2.5 |
| Siemens | SCALANCE X208PRO | All versions < V5.2.5 |
| Siemens | SCALANCE X224 | * |
| siemens | scalance_x206-1ld_firmware | 0 |
| Siemens | SCALANCE X204-2 (incl. SIPLUS NET variant) | All versions < V5.2.5 |
| Siemens | SCALANCE XF204-2 (incl. SIPLUS NET variant) | All versions < V5.2.5 |
| siemens | scalance_xf204_firmware | 0 |
| siemens | scalance_x204_irt_pro_firmware | 0 |
| siemens | scalance_x204-2ld_ts_firmware | 0 |
| siemens | scalance_x206-1_firmware | 0 |
| Siemens | SCALANCE X200-4P IRT | All versions < 5.5.1 |
| Siemens | SCALANCE XF208 | * |
| Siemens | SCALANCE X206-1LD | All versions < V5.2.5 |
| Siemens | SCALANCE XF201-3P IRT | All versions < 5.5.1 |
| siemens | scalance_xf208_firmware | 0 |
| siemens | scalance_x208pro_firmware | 0 |
| Siemens | SCALANCE X206-1 | All versions < V5.2.5 |
| siemens | scalance_xf202-2p_irt_firmware | 0 |
| Siemens | SCALANCE XF204-2BA IRT | All versions < 5.5.1 |
…and 38 more
Timeline
- Apr 13, 2021 CVE Published
- Apr 27, 2021 EPSS Score
- Jun 30, 2021 EPSS Score
- Nov 2, 2021 EPSS Score
- Jan 3, 2022 EPSS Score
- Jan 6, 2022 EPSS Score
- Mar 6, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 7, 2022 EPSS Score
- Jul 8, 2022 EPSS Score
- Nov 11, 2022 EPSS Score
- Jan 12, 2023 EPSS Score