Web Server Vulnerability in SCALANCE Products by Siemens
CVE-2021-25668
9.8CRITICAL
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 22 April 2021
What is CVE-2021-25668?
A vulnerability exists in various SCALANCE products due to improper processing of POST requests in the web server. This flaw can lead to out-of-bounds writes in the heap memory, ultimately allowing an attacker to cause a denial-of-service condition. In some scenarios, this vulnerability could be exploited to execute arbitrary code remotely, posing serious risks to the integrity and availability of the affected devices.
Affected Version(s)
SCALANCE X200-4P IRT All versions < 5.5.1
SCALANCE X201-3P IRT All versions < 5.5.1
SCALANCE X201-3P IRT PRO All versions < 5.5.1