CVE-2021-25677
published 2021-04-22CVE-2021-25677: A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions = V0.5.0.0 < V1.0.0.0), TALON TC Compact (BACnet) (All versions < V3.5.5)…
PriorityP426medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
1.06%
60.7th percentile
A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions = V0.5.0.0 < V1.0.0.0), TALON TC Compact (BACnet) (All versions < V3.5.5), TALON TC Modular (BACnet) (All versions < V3.5.5). The DNS client does not properly randomize DNS transaction IDs. That could allow an attacker to poison the DNS cache or spoof DNS resolving.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| paloalto | pan-os | — | — |
| paloalto | prisma_sd | — | — |
| siemens | apogee_pxc_compact | — | — |
| siemens | apogee_pxc_compact | — | — |
| siemens | apogee_pxc_modular | — | — |
| siemens | apogee_pxc_modular | — | — |
| siemens | nucleus_net | — | — |
| siemens | nucleus_readystart_v3 | < 2017.02.4 | 2017.02.4 |
| siemens | nucleus_readystart_v3 | — | — |
| siemens | nucleus_readystart_v3 | — | — |
| siemens | nucleus_readystart_v4 | < 4.1.0 | 4.1.0 |
| siemens | nucleus_readystart_v4 | — | — |
| siemens | nucleus_source_code | — | — |
| siemens | simotics_connect_400 | — | — |
| siemens | simotics_connect_400 | — | — |
| siemens | simotics_connect_400_firmware | >= 0.5.0.0 | — |
| siemens | talon_tc_compact | — | — |
| siemens | talon_tc_modular | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2021-0003 Informational: Impact of the NAME:WRECK DNS vulnerabilities
vendor_paloalto·2021-05-10·CVSS 9.8
[CRITICAL] PAN-SA-2021-0003 Informational: Impact of the NAME:WRECK DNS vulnerabilities
PAN-SA-2021-0003 Informational: Impact of the NAME:WRECK DNS vulnerabilities
The Palo Alto Networks Product Security Assurance team evaluated the NAME:WRECK DNS vulnerabilities impacting multiple TCP/IP software stack implementations. PAN-OS software and Prisma SD-WAN (CloudGenix) devices do not utilize the IPNet, Nucleus NET, FreeBSD, or NetX TCP/IP software stacks related to these vulnerabilities. As a result, there is no known security impact for these vulnerabilities in PAN-OS software or Prisma SD-WAN (CloudGenix) devices. CVE Summary CVE-2016-20009 This vulnerability in the IPNet TCP/IP stack does not impact PAN-OS software or Prisma SD-WAN (CloudGenix) devices. CVE-2020-15795 This vulnerability in the Nucleus NET TCP/IP stack does not impact PAN-OS software or Prisma SD-WAN (CloudG
CISA ICS
Siemens SIMOTICS CONNECT 400 (Update A)
cisa_ics·2021-04-13·CVSS 6.5
[MEDIUM] Siemens SIMOTICS CONNECT 400 (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SIMOTICS CONNECT 400 (Update A)
Last RevisedMarch 10, 2022
Alert CodeICSA-21-103-13
## 1. EXECUTIVE SUMMARY
- CVSS v3 6.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMOTICS CONNECT 400
- Vulnerabilities: Improper Null Termination, Out-of-bounds Read, Access of Memory Location After End of Buffer, Use of Insufficiently Random Values
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the original advisory titled ICSA-21-103-13 Siemens SIMOTICS CONNECT 400 that was published April 13, 2021, on the ICS webpage
GHSA
GHSA-596h-hvjh-ffpf: A vulnerability has been identified in Nucleus 4 (All versions = V0
ghsa_unreviewed·2022-05-24
CVE-2021-25677 [MEDIUM] CWE-330 GHSA-596h-hvjh-ffpf: A vulnerability has been identified in Nucleus 4 (All versions = V0
A vulnerability has been identified in Nucleus 4 (All versions = V0.5.0.0), VSTAR (versions including affected DNS modules). The DNS client does not properly randomize DNS transaction IDs. That could allow an attacker to poison the DNS cache or spoof DNS resolving.
No detection rules found.
No public exploits indexed.
https://cert-portal.siemens.com/productcert/pdf/ssa-180579.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-669158.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-705111.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-180579.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-669158.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-705111.pdf
2021-04-22
Published