VDB
SSA-979775
SSA-979775
PUBLISHED
CVSS 8.800000190734863 HIGH
Affected devices contain a stack-based buffer overflow vulnerability in the handling of STP BPDU frames that could allow a remote attacker to trigger a denial-of-service condition or potentially remote code execution. Successful exploitation requires the passive listening feature of the device to be active.
Risk Scores
CVSS 3.1
8.800000190734863
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | RUGGEDCOM RM1224 | |
| Siemens | SCALANCE XB-200 | |
| Siemens | SCALANCE S615 | |
| Siemens | SCALANCE SC-600 Family | |
| Siemens | SCALANCE XM400 | |
| Siemens | SCALANCE XC-200 | |
| Siemens | SCALANCE M-800 | |
| Siemens | SCALANCE XP-200 | |
| Siemens | SCALANCE XR-300WG | |
| Siemens | SCALANCE XF-200BA | |
| Siemens | SCALANCE XR500 |
Timeline
- Mar 9, 2021 CVE Published
- Apr 13, 2021 CVE Updated
References
- https://cert-portal.siemens.com/productcert/csaf/ssa-979775.json advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-979775.pdf advisory
- https://cert-portal.siemens.com/productcert/txt/ssa-979775.txt advisory
- https://support.industry.siemens.com/cs/ww/en/view/109794349/ advisory
- https://support.industry.siemens.com/cs/ww/en/view/109793041/ advisory
- https://support.industry.siemens.com/cs/ww/en/view/109762982/ advisory
- https://support.industry.siemens.com/cs/ww/en/view/109764409/ advisory
- https://support.industry.siemens.com/cs/ww/en/view/109761425/ advisory
- https://cert-portal.siemens.com/productcert/mitre/CVE-2021-25667.json advisory