Resource exhaustion in Siemens products - CVE-2021-31340

 

Resource exhaustion in Siemens products - CVE-2021-31340

Published: June 10, 2021


Vulnerability identifier: #VU54016
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-31340
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

SIMATIC RF166C
SIMATIC RF185C
SIMATIC RF186C
SIMATIC RF186CI
SIMATIC RF188C
SIMATIC RF188CI
SIMATIC RF360R
SIMATIC RF615R
SIMATIC RF680R
SIMATIC RF685R

How to mitigate CVE-2021-31340

Install updates from vendor's website.

SIMATIC RF166C - update to 1.3.2
SIMATIC RF185C - update to 1.3.2
SIMATIC RF186C - update to 1.3.2
SIMATIC RF186CI - update to 1.3.2
SIMATIC RF188C - update to 1.3.2
SIMATIC RF188CI - update to 1.3.2
SIMATIC RF615R - update to 3.0
SIMATIC RF680R - update to 3.0
SIMATIC RF685R - update to 3.0

External References

Related Security Bulletins