ICMP Payload Vulnerability in Capital Embedded AR and SIMOTICS CONNECT Products
CVE-2021-31346

8.2HIGH

Key Information:

Summary

A vulnerability affecting various Siemens products, including Capital Embedded AR Classic and SIMOTICS CONNECT, arises from insufficient validation of the total length of an ICMP payload specified in the IP header. This oversight could potentially lead to information leaks or Denial-of-Service scenarios, contingent upon the specific setup of the network buffer in memory. Users should be aware of the conditions that allow these issues to manifest and take appropriate action to secure their systems.

Affected Version(s)

Capital Embedded AR Classic 431-422 0

Capital Embedded AR Classic R20-11 0

PLUSCONTROL 1st Gen All versions

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.