DNS Spoofing Vulnerability in APOGEE and Nucleus Products by Siemens
CVE-2021-25677
Key Information:
- Vendor
Siemens
- Status
- Vendor
- CVE Published:
- 22 April 2021
What is CVE-2021-25677?
A significant vulnerability exists in the DNS client of various Siemens products, including the APOGEE and Nucleus series. The issue arises due to improper randomization of DNS transaction IDs, which makes the system susceptible to cache poisoning attacks and DNS spoofing. Attackers can exploit this flaw to manipulate DNS responses, potentially redirecting users to malicious sites or interfering with legitimate DNS operations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
APOGEE PXC Compact (BACnet) All versions < V3.5.5
APOGEE PXC Compact (P2 Ethernet) All versions < V2.8.20
APOGEE PXC Modular (BACnet) All versions < V3.5.5
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved