cbcvebase.
CVE-2021-27391
published 2021-09-14

CVE-2021-27391: A vulnerability has been identified in APOGEE MBC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE MEC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE…

PriorityP271critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.37%
87.4th percentile
A vulnerability has been identified in APOGEE MBC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE MEC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE PXC Compact (BACnet) (All versions = V2.8), APOGEE PXC Modular (BACnet) (All versions = V2.8), TALON TC Compact (BACnet) (All versions < V3.5.3), TALON TC Modular (BACnet) (All versions < V3.5.3). The web server of affected devices lacks proper bounds checking when parsing the Host parameter in HTTP requests, which could lead to a buffer overflow. An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary code on the device with root privileges.

Affected

16 ranges
VendorProductVersion rangeFixed in
siemensapogee_mbc
siemensapogee_mbc_firmware<= 2.6.3
siemensapogee_mec
siemensapogee_mec_firmware<= 2.6.3
siemensapogee_pxc_bacnet_automation_controller_firmware< 3.5.33.5.3
siemensapogee_pxc_compact
siemensapogee_pxc_compact
siemensapogee_pxc_compact_firmware<= 2.8
siemensapogee_pxc_modular
siemensapogee_pxc_modular
siemensapogee_pxc_modular_firmware< 3.5.33.5.3
siemensapogee_pxc_modular_firmware<= 2.8
siemenstalon_tc_compact
siemenstalon_tc_compact_firmware< 3.5.33.5.3
siemenstalon_tc_modular
siemenstalon_tc_modular_firmware< 3.5.33.5.3

Detection & IOCsextracted from sources · hover to see the quote

port80/TCP
port443/TCP
  • The vulnerability is triggered by parsing the Host header in HTTP requests — monitor for anomalously large or malformed Host header values sent to the web interface of affected Siemens APOGEE/TALON devices.
  • Exploit is unauthenticated and requires no user interaction — any inbound HTTP/HTTPS request with an oversized Host header to ports 80/TCP or 443/TCP on affected devices should be treated as suspicious.
  • No known public exploits exist as of the advisory date, but the low attack complexity (CVSS AC:L) means exploitation is straightforward once the device is reachable.
  • ·The advisory notes that parsing of 'specific requests' (not only the Host header) may trigger the overflow — the NVD description specifically calls out the Host parameter, but the CISA advisory uses broader language, so detection should not be limited solely to Host header inspection.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.