Web Server Vulnerability in SCALANCE Products by Siemens
CVE-2021-25668

9.8CRITICAL

Key Information:

Summary

A vulnerability exists in various SCALANCE products due to improper processing of POST requests in the web server. This flaw can lead to out-of-bounds writes in the heap memory, ultimately allowing an attacker to cause a denial-of-service condition. In some scenarios, this vulnerability could be exploited to execute arbitrary code remotely, posing serious risks to the integrity and availability of the affected devices.

Affected Version(s)

SCALANCE X200-4P IRT All versions < 5.5.1

SCALANCE X201-3P IRT All versions < 5.5.1

SCALANCE X201-3P IRT PRO All versions < 5.5.1

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.