Web Server Vulnerability in SCALANCE Products by Siemens
CVE-2021-25668
9.8CRITICAL
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 22 April 2021
Summary
A vulnerability exists in various SCALANCE products due to improper processing of POST requests in the web server. This flaw can lead to out-of-bounds writes in the heap memory, ultimately allowing an attacker to cause a denial-of-service condition. In some scenarios, this vulnerability could be exploited to execute arbitrary code remotely, posing serious risks to the integrity and availability of the affected devices.
Affected Version(s)
SCALANCE X200-4P IRT All versions < 5.5.1
SCALANCE X201-3P IRT All versions < 5.5.1
SCALANCE X201-3P IRT PRO All versions < 5.5.1
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved