CVE-2021-25664
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), Nucleus NET (All versions), Nucleus ReadyStart V3 (All versions < V2017.02.4), Nucleus ReadyStart V4 (All versions < V4.1.0), Nucleus Source Code (All versions including affected IPv6 stack). The function that processes the Hop-by-Hop extension header in IPv6 packets and its options lacks any checks against the length field of the header, allowing attackers to put the function into an infinite loop by supplying arbitrary length values.
Se ha identificado una vulnerabilidad en Capital VSTAR (Versiones que incluyen la pila IPv6 afectada), Nucleus NET (Todas las versiones), Nucleus ReadyStart V3 (Todas las versiones anteriores a V2017.02.4), Nucleus ReadyStart V4 (Todas las versiones anteriores a V4.1.0), Nucleus Source Code (Versiones que incluyen la pila IPv6 afectada). La función que procesa la cabecera de extensión Hop-by-Hop en los paquetes IPv6 y sus opciones carece de cualquier comprobación contra el campo de longitud de la cabecera, lo que permite a los atacantes poner la función en un bucle infinito suministrando valores de longitud arbitrarios
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-21 CVE Reserved
- 2021-04-22 CVE Published
- 2024-02-14 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://cert-portal.siemens.com/productcert/html/ssa-248289.html | ||
https://us-cert.cisa.gov/ics/advisories/icsa-21-103-05 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-248289.pdf | 2024-02-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Siemens Search vendor "Siemens" | Capital Vstar Search vendor "Siemens" for product "Capital Vstar" | - | - |
Affected
| ||||||
Siemens Search vendor "Siemens" | Nucleus Net Search vendor "Siemens" for product "Nucleus Net" | - | - |
Affected
| ||||||
Siemens Search vendor "Siemens" | Nucleus Readystart V3 Search vendor "Siemens" for product "Nucleus Readystart V3" | < 2017.02.4 Search vendor "Siemens" for product "Nucleus Readystart V3" and version " < 2017.02.4" | - |
Affected
| ||||||
Siemens Search vendor "Siemens" | Nucleus Readystart V4 Search vendor "Siemens" for product "Nucleus Readystart V4" | < 4.1.0 Search vendor "Siemens" for product "Nucleus Readystart V4" and version " < 4.1.0" | - |
Affected
| ||||||
Siemens Search vendor "Siemens" | Nucleus Source Code Search vendor "Siemens" for product "Nucleus Source Code" | - | - |
Affected
|