CVE-2021-31895
published 2021-07-13CVE-2021-31895: A vulnerability has been identified in RUGGEDCOM i800 (All versions < V4.3.7), RUGGEDCOM i801 (All versions < V4.3.7), RUGGEDCOM i802 (All versions < V4.3.7)…
PriorityP265critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.28%
81.2th percentile
A vulnerability has been identified in RUGGEDCOM i800 (All versions < V4.3.7), RUGGEDCOM i801 (All versions < V4.3.7), RUGGEDCOM i802 (All versions < V4.3.7), RUGGEDCOM i803 (All versions < V4.3.7), RUGGEDCOM M2100 (All versions < V4.3.7), RUGGEDCOM M2200 (All versions < V4.3.7), RUGGEDCOM M969 (All versions < V4.3.7), RUGGEDCOM RMC30 (All versions < V4.3.7), RUGGEDCOM RMC8388 V4.X (All versions < V4.3.7), RUGGEDCOM RMC8388 V5.X (All versions < V5.5.4), RUGGEDCOM RP110 (All versions < V4.3.7), RUGGEDCOM RS1600 (All versions < V4.3.7), RUGGEDCOM RS1600F (All versions < V4.3.7), RUGGEDCOM RS1600T (All versions < V4.3.7), RUGGEDCOM RS400 (All versions < V4.3.7), RUGGEDCOM RS401 (All versions < V4.3.7), RUGGEDCOM RS416 (All versions < V4.3.7), RUGGEDCOM RS416P (All versions < V4.3.7), RUGGEDCOM RS416Pv2 V4.X (All versions < V4.3.7), RUGGEDCOM RS416Pv2 V5.X (All versions < V5.5.4), RUGGEDCOM RS416v2 V4.X (All versions < V4.3.7), RUGGEDCOM RS416v2 V5.X (All versions < 5.5.4), RUGGEDCOM RS8000 (All versions < V4.3.7), RUGGEDCOM RS8000A (All versions < V4.3.7), RUGGEDCOM RS8000H (All versions < V4.3.7), RUGGEDCOM RS8000T (All versions < V4.3.7), RUGGEDCOM RS900 (32M) V4.X (All versions < V4.3.7), RUGGEDCOM RS900 (32M) V5.X (All versions < V5.5.4), RUGGEDCOM RS900G (All versions < V4.3.7), RUGGEDCOM RS900G (32M) V4.X (All versions < V4.3.7), RUGGEDCOM RS900G (32M) V5.X (All versions < V5.5.4), RUGGEDCOM RS900GP (All versions < V4.3.7), RUGGEDCOM RS900L (All versions < V4.3.7), RUGGEDCOM RS900W (All versions < V4.3.7), RUGGEDCOM RS910 (All versions < V4.3.7), RUGGEDCOM RS910L (All versions < V4.3.7), RUGGEDCOM RS910W (All versions < V4.3.7), RUGGEDCOM RS920L (All versions < V4.3.7), RUGGEDCOM RS920W (All versions < V4.3.7), RUGGEDCOM RS930L (All versions < V4.3.7), RUGGEDCOM RS930W (All versions < V4.3.7), RUGGEDCOM RS940G (All versions < V4.3.7), RUGGEDCOM RS969 (All versions < V4.3.7), RUGGEDCOM RSG2100 (All versions < V4.3.7), RUGGEDCOM RSG2100 (32M) V4.X (All versions < V
Affected
134 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | ruggedcom_i800 | — | — |
| siemens | ruggedcom_i801 | — | — |
| siemens | ruggedcom_i802 | — | — |
| siemens | ruggedcom_i803 | — | — |
| siemens | ruggedcom_m2100 | — | — |
| siemens | ruggedcom_m2200 | — | — |
| siemens | ruggedcom_m969 | — | — |
| siemens | ruggedcom_rmc30 | — | — |
| siemens | ruggedcom_rmc8388_v4.x | — | — |
| siemens | ruggedcom_rmc8388_v5.x | < V5.5.4 | V5.5.4 |
| siemens | ruggedcom_ros_i800 | < 4.3.7 | 4.3.7 |
| siemens | ruggedcom_ros_i801 | < 4.3.7 | 4.3.7 |
| siemens | ruggedcom_ros_i802 | < 4.3.7 | 4.3.7 |
| siemens | ruggedcom_ros_i803 | < 4.3.7 | 4.3.7 |
| siemens | ruggedcom_ros_m2100 | < 4.3.7 | 4.3.7 |
| siemens | ruggedcom_ros_m2200 | < 4.3.7 | 4.3.7 |
| siemens | ruggedcom_ros_m969 | < 4.3.7 | 4.3.7 |
| siemens | ruggedcom_ros_rmc | < 4.3.7 | 4.3.7 |
| siemens | ruggedcom_ros_rmc20 | < 4.3.7 | 4.3.7 |
| siemens | ruggedcom_ros_rmc30 | < 4.3.7 | 4.3.7 |
| siemens | ruggedcom_ros_rmc40 | < 4.3.7 | 4.3.7 |
| siemens | ruggedcom_ros_rmc41 | < 4.3.7 | 4.3.7 |
| siemens | ruggedcom_ros_rmc8388 | < 4.3.7 | 4.3.7 |
| siemens | ruggedcom_ros_rmc8388 | >= 5.0.0 < 5.5.4 | 5.5.4 |
| siemens | ruggedcom_ros_rp110 | < 4.3.7 | 4.3.7 |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is triggered via malformed/unsanitized incoming DHCP packets targeting the DHCP client on affected RUGGEDCOM ROS devices; monitor for anomalous DHCP responses (DHCP server → client traffic) directed at these devices, particularly oversized or malformed option fields that could cause buffer overflow. ↗
- →Attack vector is network (AV:N) with high complexity (AC:H), no privileges required, no user interaction — focus detection on unexpected DHCP server responses on OT/ICS network segments hosting RUGGEDCOM ROS devices. ↗
- →Enable DHCP snooping on network infrastructure to restrict DHCP responses to trusted servers only, which also serves as a detection control for rogue DHCP server activity targeting these devices. ↗
- ·The vulnerability only exists when DHCP client mode is active on the device; disabling DHCP and using a static IP address eliminates the attack surface entirely. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens RUGGEDCOM ROS
cisa_ics·2021-07-13
Siemens RUGGEDCOM ROS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens RUGGEDCOM ROS
Last RevisedJuly 13, 2021
Alert CodeICSA-21-194-10
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.1
- ATTENTION: Exploitable remotely
- Vendor: Siemens
- Equipment: RUGGEDCOM ROS
- Vulnerability: Classic Buffer Overflow
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker with network access to an affected device to cause a remote code execution condition.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following Siemens products are affected:
- RUGGEDCOM ROS i800: All versions prior to 4.3.7
- RUGGEDCOM ROS i801:
GHSA
GHSA-29cc-vcq3-44cf: A vulnerability has been identified in RUGGEDCOM ROS M2100 (All versions < V4
ghsa_unreviewed·2022-05-24
CVE-2021-31895 [CRITICAL] CWE-120 GHSA-29cc-vcq3-44cf: A vulnerability has been identified in RUGGEDCOM ROS M2100 (All versions < V4
A vulnerability has been identified in RUGGEDCOM ROS M2100 (All versions < V4.3.7), RUGGEDCOM ROS M2200 (All versions < V4.3.7), RUGGEDCOM ROS M969 (All versions < V4.3.7), RUGGEDCOM ROS RMC (All versions < V4.3.7), RUGGEDCOM ROS RMC20 (All versions < V4.3.7), RUGGEDCOM ROS RMC30 (All versions < V4.3.7), RUGGEDCOM ROS RMC40 (All versions < V4.3.7), RUGGEDCOM ROS RMC41 (All versions < V4.3.7), RUGGEDCOM ROS RMC8388 V4.X (All versions < V4.3.7), RUGGEDCOM ROS RMC8388 V5.X (All versions < V5.5.4), RUGGEDCOM ROS RP110 (All versions < V4.3.7), RUGGEDCOM ROS RS400 (All versions < V4.3.7), RUGGEDCOM ROS RS401 (All versions < V4.3.7), RUGGEDCOM ROS RS416 (All versions < V4.3.7), RUGGEDCOM ROS RS416v2 V4.X (All versions < V4.3.7), RUGGEDCOM ROS RS416v2 V5.X (All versions < 5.5.4), RUGGEDCOM ROS RS8
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-07-13
Published