Buffer Overflow Vulnerability in RUGGEDCOM RM1224 and SCALANCE Products
CVE-2021-25667
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 15 March 2021
What is CVE-2021-25667?
A stack-based buffer overflow vulnerability exists in specific RUGGEDCOM RM1224 and SCALANCE devices when handling STP BPDU frames. If exploited, a remote attacker could trigger a denial-of-service condition or potentially execute arbitrary code. The successful exploitation of this vulnerability depends on the passive listening feature being enabled on the device. Affected products include various models within the RUGGEDCOM and SCALANCE families, all of which are susceptible to this severe security loophole.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
RUGGEDCOM RM1224 All versions >= V4.3 and < V6.4
SCALANCE M-800 All versions >= V4.3 and < V6.4
SCALANCE S615 All versions >= V4.3 and < V6.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved