CVE-2021-31345

HIGH7.5Publiée le 9 novembre 2021

A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions). The total length of an UDP payload (set in the IP header) is unchecked. This may lead to various side effects, including Information Leak and Denial-of-Service conditions, depending on a user-defined applications that runs on top of the UDP protocol. (FSMD-2021-0006)

Score CVSS7.5 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Type de faiblesse (CWE)CWE-1284
Éditeurssiemens

Produits concernés

ÉditeursProdottoVersioni
siemenscapital vstar
siemensnucleus net
siemensnucleus readystart v3< 2014.12
siemensnucleus source code
siemensapogee modular building controller firmware
siemensapogee modular building controller-
siemensapogee modular equiment controller firmware
siemensapogee modular equiment controller-
siemensapogee pxc compact firmware
siemensapogee pxc compact-
siemensapogee pxc modular firmware
siemensapogee pxc modular-
siemenstalon tc compact firmware
siemenstalon tc compact-
siemenstalon tc modular firmware
siemenstalon tc modular-

Articles liés

This product uses the NVD API but is not endorsed or certified by the NVD.

Base de données CVE