CVE-2021-31889
published 2021-11-09CVE-2021-31889: A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303)…
PriorityP351critical9.1CVSS 3.1
AVNACLPRNUINSUCHINAH
EPSS
2.11%
79.6th percentile
A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions), SIMOTICS CONNECT 400 (All versions < V0.5.0.0). Malformed TCP packets with a corrupted SACK option leads to Information Leaks and Denial-of-Service conditions. (FSMD-2021-0015)
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| siemens | capital_embedded_ar_classic_431-422 | < * | * |
| siemens | capital_embedded_ar_classic_r20-11 | < V2303 | V2303 |
| siemens | nucleus_readystart_v3 | < 2017.02.3 | 2017.02.3 |
| siemens | pluscontrol_1st_gen | — | — |
| siemens | simotics_connect_400 | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9f8q-4pw9-8433: A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACn
ghsa_unreviewed·2022-05-24
CVE-2021-31889 [CRITICAL] CWE-191 GHSA-9f8q-4pw9-8433: A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACn
A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions), APOGEE PXC Compact (P2 Ethernet) (All versions), APOGEE PXC Modular (BACnet) (All versions), APOGEE PXC Modular (P2 Ethernet) (All versions), Capital VSTAR (All versions), Nucleus NET (All versions), Nucleus ReadyStart V3 (All versions < V2017.02.4), Nucleus Source Code (All versions), TALON TC Compact (BACnet) (All versions), TALON TC Modular (BACnet) (All versions). Malformed TCP packets with a corrupted SACK option leads to Information Leaks and Denial-of-Service conditions. (FSMD-2021-0015)
OSV
CVE-2021-31346: In Modem ICMP protocol integrated from Nucleus NET TCP/IP software, there is a possible out of bounds write due to a missing bounds check
osv·2022-01-01
CVE-2021-31346 CVE-2021-31346: In Modem ICMP protocol integrated from Nucleus NET TCP/IP software, there is a possible out of bounds write due to a missing bounds check
In Modem ICMP protocol integrated from Nucleus NET TCP/IP software, there is a possible out of bounds write due to a missing bounds check. This could lead to remote information disclosure or denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2021-31346: In Modem TCP protocol integrated from Nucleus NET TCP/IP software, there is a possible out of bounds write due to a missing bounds check
osv·2022-01-01
CVE-2021-31346 CVE-2021-31346: In Modem TCP protocol integrated from Nucleus NET TCP/IP software, there is a possible out of bounds write due to a missing bounds check
In Modem TCP protocol integrated from Nucleus NET TCP/IP software, there is a possible out of bounds write due to a missing bounds check. This could lead to remote information disclosure or denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2021-31346: In Modem TCP protocol integrated from Nucleus NET TCP/IP software, there is a possible system crash due to an improper input validation
osv·2022-01-01
CVE-2021-31346 CVE-2021-31346: In Modem TCP protocol integrated from Nucleus NET TCP/IP software, there is a possible system crash due to an improper input validation
In Modem TCP protocol integrated from Nucleus NET TCP/IP software, there is a possible system crash due to an improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
CISA ICS
Siemens Nucleus RTOS-based APOGEE and TALON Products (Update C)
cisa_ics·2022-04-14
Siemens Nucleus RTOS-based APOGEE and TALON Products (Update C)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens Nucleus RTOS-based APOGEE and TALON Products (Update C)
Last RevisedMay 12, 2022
Alert CodeICSA-21-315-07
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: Nucleus RTOS based APOGEE and TALON Products
- Vulnerabilities: Type Confusion, Improper Validation of Specified Quantity in Input, Out-of-bounds Read, Improper Restriction of Operations within the Bounds of a Memory Buffer, Improper Null Termination, Buffer Access with Incorrect Length Value, Integer Underflow, Improper Handling of Inconsi
CISA ICS
Siemens SIMOTICS CONNECT 400
cisa_ics·2022-03-10·CVSS 6.9
[MEDIUM] Siemens SIMOTICS CONNECT 400
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SIMOTICS CONNECT 400
Last RevisedMarch 10, 2022
Alert CodeICSA-22-069-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.2
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMOTICS CONNECT 400
- Vulnerabilities: Type Confusion, Improper Validation of Specified Quantity in Input, Wrap or Wraparound, Improper Handling of Inconsistent Structural Elements
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could lead to information leaks or a denial-of-service condition.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Th
CISA ICS
Siemens Energy PLUSCONTROL
cisa_ics·2022-01-13·CVSS 6.9
[MEDIUM] Siemens Energy PLUSCONTROL
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens Energy PLUSCONTROL
Last RevisedJanuary 13, 2022
Alert CodeICSA-22-013-03
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.2
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens Energy
- Equipment: PLUSCONTROL
- Vulnerabilities: Type Confusion, Improper Validation of Specified Quantity in Input, Buffer Access with Incorrect Length Value, Integer Underflow, Improper Handling of Inconsistent Structural Elements
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could result in access to TFTP memory buffer contents, information leaks, and de
Android
CVE-2021-31889: Modem (Nucleus NET TCP/IP)
vendor_android·2022-01-01·CVSS 7.5
CVE-2021-31889 [HIGH] CVE-2021-31889: Modem (Nucleus NET TCP/IP)
Android Security Bulletin 2022-01-01
CVE: CVE-2021-31889
Severity: HIGH
Component: Modem (Nucleus NET TCP/IP)
References: A-207646335
M-MOLY00756840 *
CISA ICS
Siemens Capital VSTAR (Update A)
cisa_ics·2021-12-16·CVSS 6.9
[MEDIUM] Siemens Capital VSTAR (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens Capital VSTAR (Update A)
Last RevisedNovember 10, 2022
Alert CodeICSA-21-350-06
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.8
- ATTENTION: Exploitable remotely / Low attack complexity
- Vendor: Siemens
- Equipment: Capital VSTAR
- Vulnerabilities: Access of Resource Using Incompatible Type, Improper Validation of Specified Quantity in Input, Out-of-Bounds Read, Improper Restriction of Operations within the Bounds of a Memory Buffer, Improper Null Termination, Integer Underflow, Improper Handling of Inconsistent Structural Elements
## 2 UPDATE OR REPOSTED INFORMATION
This u
CISA ICS
Siemens Nucleus RTOS TCP/IP Stack
cisa_ics·2021-11-17
Siemens Nucleus RTOS TCP/IP Stack
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens Nucleus RTOS TCP/IP Stack
Last RevisedNovember 17, 2021
Alert CodeICSA-21-313-03
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: Nucleus Net, Nucleus ReadyStart, Capital VSTAR
- Vulnerabilities: Type Confusion, Improper Validation of Specified Quantity in Input, Out-of-bounds Read, Improper Restriction of Operations within the Bounds of a Memory Buffer, Improper Null Termination, Buffer Access with Incorrect Length Value, Integer Underflow, Improper Handling of Inconsistent Structural Elemen
No detection rules found.
No public exploits indexed.
https://cert-portal.siemens.com/productcert/html/ssa-044112.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-114589.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-223353.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-620288.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-845392.htmlhttps://cert-portal.siemens.com/productcert/pdf/ssa-044112.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-114589.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-223353.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-620288.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-845392.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-044112.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-114589.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-223353.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-620288.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-845392.pdf
2021-11-09
Published