VDB

CVE-2021-25668

CVE-2021-25668 PUBLISHED CVSS 9.800000190734863 CRITICAL

A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < 5.5.1), SCALANCE X201-3P IRT (All versions < 5.5.1), SCALANCE X201-3P IRT PRO (All versions < 5.5.1), SCALANCE X202-2 IRT (All versions < 5.5.1), SCALANCE X202-2P IRT (incl. SIPLUS NET variant) (All versions < 5.5.1), SCALANCE X202-2P IRT PRO (All versions < 5.5.1), SCALANCE X204 IRT (All versions < 5.5.1), SCALANCE X204 IRT PRO (All versions < 5.5.1), SCALANCE X204-2 (incl. SIPLUS NET variant) (All versions), SCALANCE X204-2FM (All versions), SCALANCE X204-2LD (incl. SIPLUS NET variant) (All versions), SCALANCE X204-2LD TS (All versions), SCALANCE X204-2TS (All versions), SCALANCE X206-1 (All versions), SCALANCE X206-1LD (All versions), SCALANCE X208 (incl. SIPLUS NET variant) (All versions), SCALANCE X208PRO (All versions), SCALANCE X212-2 (incl. SIPLUS NET variant) (All versions), SCALANCE X212-2LD (All versions), SCALANCE X216 (All versions), SCALANCE X224 (All versions), SCALANCE XF201-3P IRT (All versions < 5.5.1), SCALANCE XF202-2P IRT (All versions < 5.5.1), SCALANCE XF204 (All versions), SCALANCE XF204 IRT (All versions < 5.5.1), SCALANCE XF204-2 (incl. SIPLUS NET variant) (All versions), SCALANCE XF204-2BA IRT (All versions < 5.5.1), SCALANCE XF206-1 (All versions), SCALANCE XF208 (All versions). Incorrect processing of POST requests in the webserver may result in write out of bounds in heap. An attacker might leverage this to cause denial-of-service on the device and potentially remotely execute code.

EPSS 1.28% · 79.9th percentile

Risk Scores

CVSS v3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
1.28%
79.9th percentile

Affected Products

VendorProductVersions
SiemensSCALANCE X202-2 IRTAll versions < 5.5.1
SiemensSCALANCE XF204All versions < V5.2.5
SiemensSCALANCE X208PROAll versions < V5.2.5
SiemensSCALANCE X224*
siemensscalance_x206-1ld_firmware0
SiemensSCALANCE X204-2 (incl. SIPLUS NET variant)All versions < V5.2.5
SiemensSCALANCE XF204-2 (incl. SIPLUS NET variant)All versions < V5.2.5
siemensscalance_xf204_firmware0
siemensscalance_x204_irt_pro_firmware0
siemensscalance_x204-2ld_ts_firmware0
siemensscalance_x206-1_firmware0
SiemensSCALANCE X200-4P IRTAll versions < 5.5.1
SiemensSCALANCE XF208*
SiemensSCALANCE X206-1LDAll versions < V5.2.5
SiemensSCALANCE XF201-3P IRTAll versions < 5.5.1
siemensscalance_xf208_firmware0
siemensscalance_x208pro_firmware0
SiemensSCALANCE X206-1All versions < V5.2.5
siemensscalance_xf202-2p_irt_firmware0
SiemensSCALANCE XF204-2BA IRTAll versions < 5.5.1

…and 38 more

Timeline

  • Apr 13, 2021 CVE Published
  • Apr 27, 2021 EPSS Score
  • Jun 30, 2021 EPSS Score
  • Nov 2, 2021 EPSS Score
  • Jan 3, 2022 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Mar 6, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 7, 2022 EPSS Score
  • Jul 8, 2022 EPSS Score
  • Nov 11, 2022 EPSS Score
  • Jan 12, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›