OSPF Protocol Vulnerability in SCALANCE Network Devices by Siemens
CVE-2021-37182
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 14 June 2022
What is CVE-2021-37182?
A vulnerability exists in multiple SCALANCE network devices from Siemens where the OSPF protocol implementation does not properly validate the checksum and length fields of OSPF LS Update messages. This flaw enables an unauthenticated remote attacker to disrupt network services by sending specially crafted OSPF packets. For successful exploitation, OSPF must be enabled on the target device, potentially leading to significant network interruptions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SCALANCE XM408-4C All versions < V6.5
SCALANCE XM408-4C (L3 int.) All versions < V6.5
SCALANCE XM408-8C All versions < V6.5
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved