Use of insufficiently random values in Siemens products - CVE-2021-27393
Published: April 14, 2021 / Updated: April 15, 2021
Vulnerability identifier: #VU52207
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-27393
CWE-ID: CWE-330
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the DNS client does not properly randomize UDP port numbers of DNS requests. A remote attacker can poison the DNS cache or spoof DNS resolving.
Affected software
Nucleus NET
Nucleus RTOS
Nucleus Source Code
VSTAR
Nucleus ReadyStart
Nucleus RTOS
Nucleus Source Code
VSTAR
Nucleus ReadyStart
How to mitigate CVE-2021-27393
Install updates from vendor's website.
Nucleus ReadyStart - update to 2013.08