Type Confusion in Siemens products - CVE-2021-31344

 

Type Confusion in Siemens products - CVE-2021-31344

Published: November 10, 2021


Vulnerability identifier: #VU58078
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-31344
CWE-ID: CWE-843
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the system.

The vulnerability exists due to a type confusion error within ICMP echo packets with fake IP options. A remote attacker can send specially crafted ICMP echo reply messages to arbitrary hosts on the network.


Affected software

Nucleus NET
Nucleus Source Code
Capital VSTAR
Nucleus ReadyStart
APOGEE MBC (PPC) (BACnet)
APOGEE MBC (PPC) (P2 Ethernet)
APOGEE MEC (PPC) (BACnet)
APOGEE MEC (PPC) (P2 Ethernet)
APOGEE PXC Compact (BACnet)
APOGEE PXC Compact (P2 Ethernet)
APOGEE PXC Modular (BACnet)
APOGEE PXC Modular (P2 Ethernet)
TALON TC Compact (BACnet)
TALON TC Modular (BACnet)
SIMOTICS CONNECT 400
PLUSCONTROL 1st Gen

How to mitigate CVE-2021-31344

Install updates from vendor's website.

Nucleus ReadyStart - addressed in versions 4.1.1, 2017.02.4
SIMOTICS CONNECT 400 - update to 1.0.0.0

External References

Related Security Bulletins