VDB

CVE-2021-37182

CVE-2021-37182 PUBLISHED CVSS 4.300000190734863 MEDIUM

A vulnerability has been identified in SCALANCE XM408-4C (All versions < V6.5), SCALANCE XM408-4C (L3 int.) (All versions < V6.5), SCALANCE XM408-8C (All versions < V6.5), SCALANCE XM408-8C (L3 int.) (All versions < V6.5), SCALANCE XM416-4C (All versions < V6.5), SCALANCE XM416-4C (L3 int.) (All versions < V6.5), SCALANCE XR524-8C, 1x230V (All versions < V6.5), SCALANCE XR524-8C, 1x230V (L3 int.) (All versions < V6.5), SCALANCE XR524-8C, 24V (All versions < V6.5), SCALANCE XR524-8C, 24V (L3 int.) (All versions < V6.5), SCALANCE XR524-8C, 2x230V (All versions < V6.5), SCALANCE XR524-8C, 2x230V (L3 int.) (All versions < V6.5), SCALANCE XR526-8C, 1x230V (All versions < V6.5), SCALANCE XR526-8C, 1x230V (L3 int.) (All versions < V6.5), SCALANCE XR526-8C, 24V (All versions < V6.5), SCALANCE XR526-8C, 24V (L3 int.) (All versions < V6.5), SCALANCE XR526-8C, 2x230V (All versions < V6.5), SCALANCE XR526-8C, 2x230V (L3 int.) (All versions < V6.5), SCALANCE XR528-6M (All versions < V6.5), SCALANCE XR528-6M (2HR2) (All versions < V6.5), SCALANCE XR528-6M (2HR2, L3 int.) (All versions < V6.5), SCALANCE XR528-6M (L3 int.) (All versions < V6.5), SCALANCE XR552-12M (All versions < V6.5), SCALANCE XR552-12M (2HR2) (All versions < V6.5), SCALANCE XR552-12M (2HR2) (All versions < V6.5), SCALANCE XR552-12M (2HR2, L3 int.) (All versions < V6.5). The OSPF protocol implementation in affected devices fails to verify the checksum and length fields in the OSPF LS Update messages. An unauthenticated remote attacker could exploit this vulnerability to cause interruptions in the network by sending specially crafted OSPF packets. Successful exploitation requires OSPF to be enabled on an affected device.

EPSS 0.20% · 42.3th percentile

Risk Scores

CVSS 2.0
4.300000190734863
EPSS Score
0.20%
42.3th percentile

Affected Products

VendorProductVersions
siemensscalance_xm408-8c_firmware0
siemensscalance_xm416-4c_firmware0
SiemensSCALANCE XR526-8C, 1x230V*
SiemensSCALANCE XM416-4CAll versions < V6.5
siemensscalance_xr552-12m_2hr2_l3_firmware0
SiemensSCALANCE XR552-12M (2HR2)*, All versions < V6.5
siemensscalance_xr528-6m_2hr2_firmware0
siemensscalance_xm416-4c_l3_firmware0
SiemensSCALANCE XR524-8C, 24VAll versions < V6.5
SiemensSCALANCE XM408-4C (L3 int.)All versions < V6.5
SiemensSCALANCE XR524-8C, 2x230VAll versions < V6.5
SiemensSCALANCE XR526-8C, 2x230VAll versions < V6.5
siemensscalance_xm408-4c_l3_firmware0
siemensscalance_xm408-4c_firmware0
SiemensSCALANCE XM408-8C*
SiemensSCALANCE XR528-6M (2HR2)All versions < V6.5
siemensscalance_xr524-8c_firmware0, 0, 0
siemensscalance_xr524-8c_l3_firmware0, 0, 0
SiemensSCALANCE XM408-4CAll versions < V6.5
SiemensSCALANCE XR526-8C, 1x230V (L3 int.)All versions < V6.5

…and 22 more

Timeline

  • Jun 14, 2022 CVE Published
  • Jun 15, 2022 EPSS Score
  • Aug 3, 2022 EPSS Score
  • Sep 20, 2022 EPSS Score
  • Nov 7, 2022 EPSS Score
  • Dec 25, 2022 EPSS Score
  • Feb 11, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 31, 2023 EPSS Score
  • May 18, 2023 EPSS Score
  • Jul 6, 2023 EPSS Score
  • Aug 23, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›