CVE-2021-27391
published 2021-09-14CVE-2021-27391: A vulnerability has been identified in APOGEE MBC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE MEC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE…
PriorityP271critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.37%
87.4th percentile
A vulnerability has been identified in APOGEE MBC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE MEC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE PXC Compact (BACnet) (All versions = V2.8), APOGEE PXC Modular (BACnet) (All versions = V2.8), TALON TC Compact (BACnet) (All versions < V3.5.3), TALON TC Modular (BACnet) (All versions < V3.5.3). The web server of affected devices lacks proper bounds checking when parsing the Host parameter in HTTP requests, which could lead to a buffer overflow. An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary code on the device with root privileges.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | apogee_mbc | — | — |
| siemens | apogee_mbc_firmware | <= 2.6.3 | — |
| siemens | apogee_mec | — | — |
| siemens | apogee_mec_firmware | <= 2.6.3 | — |
| siemens | apogee_pxc_bacnet_automation_controller_firmware | < 3.5.3 | 3.5.3 |
| siemens | apogee_pxc_compact | — | — |
| siemens | apogee_pxc_compact | — | — |
| siemens | apogee_pxc_compact_firmware | <= 2.8 | — |
| siemens | apogee_pxc_modular | — | — |
| siemens | apogee_pxc_modular | — | — |
| siemens | apogee_pxc_modular_firmware | < 3.5.3 | 3.5.3 |
| siemens | apogee_pxc_modular_firmware | <= 2.8 | — |
| siemens | talon_tc_compact | — | — |
| siemens | talon_tc_compact_firmware | < 3.5.3 | 3.5.3 |
| siemens | talon_tc_modular | — | — |
| siemens | talon_tc_modular_firmware | < 3.5.3 | 3.5.3 |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is triggered by parsing the Host header in HTTP requests — monitor for anomalously large or malformed Host header values sent to the web interface of affected Siemens APOGEE/TALON devices. ↗
- →Exploit is unauthenticated and requires no user interaction — any inbound HTTP/HTTPS request with an oversized Host header to ports 80/TCP or 443/TCP on affected devices should be treated as suspicious. ↗
- →No known public exploits exist as of the advisory date, but the low attack complexity (CVSS AC:L) means exploitation is straightforward once the device is reachable. ↗
- ·The advisory notes that parsing of 'specific requests' (not only the Host header) may trigger the overflow — the NVD description specifically calls out the Host parameter, but the CISA advisory uses broader language, so detection should not be limited solely to Host header inspection. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens APOGEE and TALON
cisa_ics·2021-09-14·CVSS 9.8
[CRITICAL] Siemens APOGEE and TALON
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens APOGEE and TALON
Last RevisedSeptember 14, 2021
Alert CodeICSA-21-257-07
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: APOGEE and TALON
- Vulnerability: Classic Buffer Overflow
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the device with root privileges.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following products are affected:
- APOGEE MBC (PPC) (P2 Ethernet): v2.6.3 and newer
- APOGEE MEC (PPC)
GHSA
GHSA-98pm-v23p-r2wf: A vulnerability has been identified in APOGEE MBC (PPC) (P2 Ethernet) (All versions >= V2
ghsa_unreviewed·2022-05-24
CVE-2021-27391 [CRITICAL] CWE-120 GHSA-98pm-v23p-r2wf: A vulnerability has been identified in APOGEE MBC (PPC) (P2 Ethernet) (All versions >= V2
A vulnerability has been identified in APOGEE MBC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE MEC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE PXC Compact (BACnet) (All versions = V2.8), APOGEE PXC Modular (BACnet) (All versions = V2.8), TALON TC Compact (BACnet) (All versions < V3.5.3), TALON TC Modular (BACnet) (All versions < V3.5.3). The web server of affected devices lacks proper bounds checking when parsing the Host parameter in HTTP requests, which could lead to a buffer overflow. An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary code on the device with root privileges.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-09-14
Published