Out-of-bounds read in Siemens products - CVE-2021-31885
Published: November 10, 2021
Vulnerability identifier: #VU58085
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-31885
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition. A remote attacker can send specially crafted TFTP commands, trigger out-of-bounds read error and read contents of memory on the system.
Affected software
Nucleus NET
Nucleus Source Code
Capital VSTAR
Nucleus ReadyStart
APOGEE MBC (PPC) (BACnet)
APOGEE MBC (PPC) (P2 Ethernet)
APOGEE MEC (PPC) (BACnet)
APOGEE MEC (PPC) (P2 Ethernet)
APOGEE PXC Compact (BACnet)
APOGEE PXC Compact (P2 Ethernet)
APOGEE PXC Modular (BACnet)
APOGEE PXC Modular (P2 Ethernet)
TALON TC Compact (BACnet)
TALON TC Modular (BACnet)
PLUSCONTROL 1st Gen
Nucleus Source Code
Capital VSTAR
Nucleus ReadyStart
APOGEE MBC (PPC) (BACnet)
APOGEE MBC (PPC) (P2 Ethernet)
APOGEE MEC (PPC) (BACnet)
APOGEE MEC (PPC) (P2 Ethernet)
APOGEE PXC Compact (BACnet)
APOGEE PXC Compact (P2 Ethernet)
APOGEE PXC Modular (BACnet)
APOGEE PXC Modular (P2 Ethernet)
TALON TC Compact (BACnet)
TALON TC Modular (BACnet)
PLUSCONTROL 1st Gen
How to mitigate CVE-2021-31885
Install updates from vendor's website.
Nucleus ReadyStart - addressed in versions 4.1.1, 2017.02.4