CVE-2021-31886
published 2021-11-09CVE-2021-31886: A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All…
PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.03%
85.9th percentile
A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions = V2.3 and = V2.3 and = V2.3 and = V2.3 and = V2.3 and = V2.3 and = V2.3 and = V2.3 and = V2.3 and = V2.3 and = V2.3 and = V2.3 and = V2.3 and < V6.30.016), Nucleus NET (All versions), Nucleus ReadyStart V3 (All versions < V2017.02.4), Nucleus Source Code (All versions), TALON TC Compact (BACnet) (All versions < V3.5.4), TALON TC Modular (BACnet) (All versions < V3.5.4). FTP server does not properly validate the length of the “USER” command, leading to stack-based buffer overflows. This may result in Denial-of-Service conditions and Remote Code Execution. (FSMD-2021-0010)
Affected
44 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | apogee_mbc | — | — |
| siemens | apogee_mec | — | — |
| siemens | apogee_pxc_compact | — | — |
| siemens | apogee_pxc_compact | — | — |
| siemens | apogee_pxc_compact_firmware | < 2.8.19 | 2.8.19 |
| siemens | apogee_pxc_compact_firmware | < 3.5.4 | 3.5.4 |
| siemens | apogee_pxc_modular | — | — |
| siemens | apogee_pxc_modular | — | — |
| siemens | apogee_pxc_modular_firmware | < 2.8.19 | 2.8.19 |
| siemens | apogee_pxc_modular_firmware | < 3.5.4 | 3.5.4 |
| siemens | desigo_pxc00-e.d | — | — |
| siemens | desigo_pxc00-e.d_firmware | >= 2.3 < 6.30.016 | 6.30.016 |
| siemens | desigo_pxc00-u | — | — |
| siemens | desigo_pxc00-u_firmware | >= 2.3 < 6.30.016 | 6.30.016 |
| siemens | desigo_pxc001-e.d | — | — |
| siemens | desigo_pxc001-e.d_firmware | >= 2.3 < 6.30.016 | 6.30.016 |
| siemens | desigo_pxc100-e.d | — | — |
| siemens | desigo_pxc100-e.d_firmware | >= 2.3 < 6.30.016 | 6.30.016 |
| siemens | desigo_pxc12-e.d | — | — |
| siemens | desigo_pxc12-e.d_firmware | >= 2.3 < 6.30.016 | 6.30.016 |
| siemens | desigo_pxc128-u | — | — |
| siemens | desigo_pxc128-u_firmware | >= 2.3 < 6.30.016 | 6.30.016 |
| siemens | desigo_pxc200-e.d | — | — |
| siemens | desigo_pxc200-e.d_firmware | >= 2.3 < 6.30.016 | 6.30.016 |
| siemens | desigo_pxc22-e.d | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p584-873g-v9x6: A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACn
ghsa_unreviewed·2022-05-24
CVE-2021-31886 [CRITICAL] CWE-170 GHSA-p584-873g-v9x6: A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACn
A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions), APOGEE PXC Compact (P2 Ethernet) (All versions), APOGEE PXC Modular (BACnet) (All versions), APOGEE PXC Modular (P2 Ethernet) (All versions), Capital VSTAR (All versions), Nucleus NET (All versions), Nucleus ReadyStart V3 (All versions < V2017.02.4), Nucleus Source Code (All versions), TALON TC Compact (BACnet) (All versions), TALON TC Modular (BACnet) (All versions). FTP server does not properly validate the length of the “USER” command, leading to stack-based buffer overflows. This may result in Denial-of-Service conditions and Rem
CISA ICS
Siemens Nucleus RTOS-based APOGEE and TALON Products (Update C)
cisa_ics·2022-04-14
Siemens Nucleus RTOS-based APOGEE and TALON Products (Update C)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens Nucleus RTOS-based APOGEE and TALON Products (Update C)
Last RevisedMay 12, 2022
Alert CodeICSA-21-315-07
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: Nucleus RTOS based APOGEE and TALON Products
- Vulnerabilities: Type Confusion, Improper Validation of Specified Quantity in Input, Out-of-bounds Read, Improper Restriction of Operations within the Bounds of a Memory Buffer, Improper Null Termination, Buffer Access with Incorrect Length Value, Integer Underflow, Improper Handling of Inconsi
CISA ICS
Siemens Nucleus RTOS TCP/IP Stack
cisa_ics·2021-11-17
Siemens Nucleus RTOS TCP/IP Stack
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens Nucleus RTOS TCP/IP Stack
Last RevisedNovember 17, 2021
Alert CodeICSA-21-313-03
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: Nucleus Net, Nucleus ReadyStart, Capital VSTAR
- Vulnerabilities: Type Confusion, Improper Validation of Specified Quantity in Input, Out-of-bounds Read, Improper Restriction of Operations within the Bounds of a Memory Buffer, Improper Null Termination, Buffer Access with Incorrect Length Value, Integer Underflow, Improper Handling of Inconsistent Structural Elemen
No detection rules found.
No public exploits indexed.
2021-11-09
Published