// For flags

CVE-2021-31887

 

Severity Score

8.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions < V3.5.4), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.19), APOGEE PXC Modular (BACnet) (All versions < V3.5.4), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.19), Desigo PXC00-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC00-U (All versions >= V2.3 and < V6.30.016), Desigo PXC001-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC100-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC12-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC128-U (All versions >= V2.3 and < V6.30.016), Desigo PXC200-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC22-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC22.1-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC36.1-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC50-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC64-U (All versions >= V2.3 and < V6.30.016), Desigo PXM20-E (All versions >= V2.3 and < V6.30.016), Nucleus NET (All versions), Nucleus ReadyStart V3 (All versions < V2017.02.4), Nucleus Source Code (All versions), TALON TC Compact (BACnet) (All versions < V3.5.4), TALON TC Modular (BACnet) (All versions < V3.5.4). FTP server does not properly validate the length of the “PWD/XPWD” command, leading to stack-based buffer overflows. This may result in Denial-of-Service conditions and Remote Code Execution. (FSMD-2021-0016)

Se ha identificado una vulnerabilidad en APOGEE MBC (PPC) (BACnet) (Todas las versiones), APOGEE MBC (PPC) (P2 Ethernet) (Todas las versiones), APOGEE MEC (PPC) (BACnet) (Todas las versiones), APOGEE MEC (PPC) (P2 Ethernet) (Todas las versiones), APOGEE PXC Compact (BACnet) (Todas las versiones anteriores a V3. 5.4), APOGEE PXC Compact (P2 Ethernet) (Todas las versiones anteriores a V2.8.19), APOGEE PXC Modular (BACnet) (Todas las versiones anteriores a V3. 5.4), APOGEE PXC Modular (P2 Ethernet) (Todas las versiones anteriores a V2.8.19), Desigo PXC00-E.D (Todas las versiones posteriores o iguales a V2.3 y anteriores a V6.30.016), Desigo PXC00-U (Todas las versiones posteriores o iguales a V2.3 y anteriores a V6. 30.016), Desigo PXC001-E.D (Todas las versiones posteriores o iguales a V2.3 y anteriores a V6.30.016), Desigo PXC100-E.D (Todas las versiones posteriores o iguales a V2.3 y anteriores a V6.30.016), Desigo PXC12-E.D (Todas las versiones posteriores o iguales a V2. 3 y anteriores a V6.30.016), Desigo PXC128-U (Todas las versiones posteriores o iguales a V2.3 y anteriores a V6.30.016), Desigo PXC200-E.D (Todas las versiones posteriores o iguales a V2.3 y anteriores a V6.30.016), Desigo PXC22-E.D (Todas las versiones posteriores o iguales a V2. 3 y anteriores a V6.30.016), Desigo PXC22.1-E.D (Todas las versiones posteriores o iguales a V2.3 y anteriores a V6.30.016), Desigo PXC36.1-E.D (Todas las versiones posteriores o iguales a V2.3 y anteriores a V6.30.016), Desigo PXC50-E.D (Todas las versiones posteriores o iguales a V2. 3 y anteriores a V6.30.016), Desigo PXC64-U (Todas las versiones posteriores o iguales a V2.3 y anteriores a V6.30.016), Desigo PXM20-E (Todas las versiones posteriores o iguales a V2.3 y anteriores a V6.30.016), Nucleus NET (Todas las versiones), Nucleus ReadyStart V3 (Todas las versiones anteriores a V2017. 02.4), Nucleus Source Code (Todas las versiones), TALON TC Compact (BACnet) (Todas las versiones anteriores a V3.5.4), TALON TC Modular (BACnet) (Todas las versiones anteriores a V3.5.4). El servidor FTP no valida correctamente la longitud del comando "PWD/XPWD", lo que lleva a desbordamientos de búfer basados en la pila. Esto puede provocar condiciones de denegación de servicio y ejecución remota de código. (FSMD-2021-0016)

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-04-29 CVE Reserved
  • 2021-11-09 CVE Published
  • 2024-02-01 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-170: Improper Null Termination
  • CWE-787: Out-of-bounds Write
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Siemens
Search vendor "Siemens"
Apogee Modular Building Controller Firmware
Search vendor "Siemens" for product "Apogee Modular Building Controller Firmware"
*-
Affected
in Siemens
Search vendor "Siemens"
Apogee Modular Building Controller
Search vendor "Siemens" for product "Apogee Modular Building Controller"
--
Safe
Siemens
Search vendor "Siemens"
Apogee Modular Equiment Controller Firmware
Search vendor "Siemens" for product "Apogee Modular Equiment Controller Firmware"
*-
Affected
in Siemens
Search vendor "Siemens"
Apogee Modular Equiment Controller
Search vendor "Siemens" for product "Apogee Modular Equiment Controller"
--
Safe
Siemens
Search vendor "Siemens"
Apogee Pxc Compact Firmware
Search vendor "Siemens" for product "Apogee Pxc Compact Firmware"
< 2.8.19
Search vendor "Siemens" for product "Apogee Pxc Compact Firmware" and version " < 2.8.19"
p2_ethernet
Affected
in Siemens
Search vendor "Siemens"
Apogee Pxc Compact
Search vendor "Siemens" for product "Apogee Pxc Compact"
--
Safe
Siemens
Search vendor "Siemens"
Apogee Pxc Compact Firmware
Search vendor "Siemens" for product "Apogee Pxc Compact Firmware"
< 3.5.4
Search vendor "Siemens" for product "Apogee Pxc Compact Firmware" and version " < 3.5.4"
bacnet
Affected
in Siemens
Search vendor "Siemens"
Apogee Pxc Compact
Search vendor "Siemens" for product "Apogee Pxc Compact"
--
Safe
Siemens
Search vendor "Siemens"
Apogee Pxc Modular Firmware
Search vendor "Siemens" for product "Apogee Pxc Modular Firmware"
< 2.8.19
Search vendor "Siemens" for product "Apogee Pxc Modular Firmware" and version " < 2.8.19"
p2_ethernet
Affected
in Siemens
Search vendor "Siemens"
Apogee Pxc Modular
Search vendor "Siemens" for product "Apogee Pxc Modular"
--
Safe
Siemens
Search vendor "Siemens"
Apogee Pxc Modular Firmware
Search vendor "Siemens" for product "Apogee Pxc Modular Firmware"
< 3.5.4
Search vendor "Siemens" for product "Apogee Pxc Modular Firmware" and version " < 3.5.4"
bacnet
Affected
in Siemens
Search vendor "Siemens"
Apogee Pxc Modular
Search vendor "Siemens" for product "Apogee Pxc Modular"
--
Safe
Siemens
Search vendor "Siemens"
Talon Tc Compact Firmware
Search vendor "Siemens" for product "Talon Tc Compact Firmware"
< 3.5.4
Search vendor "Siemens" for product "Talon Tc Compact Firmware" and version " < 3.5.4"
-
Affected
in Siemens
Search vendor "Siemens"
Talon Tc Compact
Search vendor "Siemens" for product "Talon Tc Compact"
--
Safe
Siemens
Search vendor "Siemens"
Talon Tc Modular Firmware
Search vendor "Siemens" for product "Talon Tc Modular Firmware"
< 3.5.4
Search vendor "Siemens" for product "Talon Tc Modular Firmware" and version " < 3.5.4"
-
Affected
in Siemens
Search vendor "Siemens"
Talon Tc Modular
Search vendor "Siemens" for product "Talon Tc Modular"
--
Safe
Siemens
Search vendor "Siemens"
Desigo Pxc00-e.d Firmware
Search vendor "Siemens" for product "Desigo Pxc00-e.d Firmware"
>= 2.3 < 6.30.016
Search vendor "Siemens" for product "Desigo Pxc00-e.d Firmware" and version " >= 2.3 < 6.30.016"
-
Affected
in Siemens
Search vendor "Siemens"
Desigo Pxc00-e.d
Search vendor "Siemens" for product "Desigo Pxc00-e.d"
--
Safe
Siemens
Search vendor "Siemens"
Desigo Pxc00-u Firmware
Search vendor "Siemens" for product "Desigo Pxc00-u Firmware"
>= 2.3 < 6.30.016
Search vendor "Siemens" for product "Desigo Pxc00-u Firmware" and version " >= 2.3 < 6.30.016"
-
Affected
in Siemens
Search vendor "Siemens"
Desigo Pxc00-u
Search vendor "Siemens" for product "Desigo Pxc00-u"
--
Safe
Siemens
Search vendor "Siemens"
Desigo Pxc001-e.d Firmware
Search vendor "Siemens" for product "Desigo Pxc001-e.d Firmware"
>= 2.3 < 6.30.016
Search vendor "Siemens" for product "Desigo Pxc001-e.d Firmware" and version " >= 2.3 < 6.30.016"
-
Affected
in Siemens
Search vendor "Siemens"
Desigo Pxc001-e.d
Search vendor "Siemens" for product "Desigo Pxc001-e.d"
--
Safe
Siemens
Search vendor "Siemens"
Desigo Pxc12-e.d Firmware
Search vendor "Siemens" for product "Desigo Pxc12-e.d Firmware"
>= 2.3 < 6.30.016
Search vendor "Siemens" for product "Desigo Pxc12-e.d Firmware" and version " >= 2.3 < 6.30.016"
-
Affected
in Siemens
Search vendor "Siemens"
Desigo Pxc12-e.d
Search vendor "Siemens" for product "Desigo Pxc12-e.d"
--
Safe
Siemens
Search vendor "Siemens"
Desigo Pxc22-e.d Firmware
Search vendor "Siemens" for product "Desigo Pxc22-e.d Firmware"
>= 2.3 < 6.30.016
Search vendor "Siemens" for product "Desigo Pxc22-e.d Firmware" and version " >= 2.3 < 6.30.016"
-
Affected
in Siemens
Search vendor "Siemens"
Desigo Pxc22-e.d
Search vendor "Siemens" for product "Desigo Pxc22-e.d"
--
Safe
Siemens
Search vendor "Siemens"
Desigo Pxc22.1-e.d Firmware
Search vendor "Siemens" for product "Desigo Pxc22.1-e.d Firmware"
>= 2.3 < 6.30.016
Search vendor "Siemens" for product "Desigo Pxc22.1-e.d Firmware" and version " >= 2.3 < 6.30.016"
-
Affected
in Siemens
Search vendor "Siemens"
Desigo Pxc22.1-e.d
Search vendor "Siemens" for product "Desigo Pxc22.1-e.d"
--
Safe
Siemens
Search vendor "Siemens"
Desigo Pxc36.1-e.d Firmware
Search vendor "Siemens" for product "Desigo Pxc36.1-e.d Firmware"
>= 2.3 < 6.30.016
Search vendor "Siemens" for product "Desigo Pxc36.1-e.d Firmware" and version " >= 2.3 < 6.30.016"
-
Affected
in Siemens
Search vendor "Siemens"
Desigo Pxc36.1-e.d
Search vendor "Siemens" for product "Desigo Pxc36.1-e.d"
--
Safe
Siemens
Search vendor "Siemens"
Desigo Pxc50-e.d Firmware
Search vendor "Siemens" for product "Desigo Pxc50-e.d Firmware"
>= 2.3 < 6.30.016
Search vendor "Siemens" for product "Desigo Pxc50-e.d Firmware" and version " >= 2.3 < 6.30.016"
-
Affected
in Siemens
Search vendor "Siemens"
Desigo Pxc50-e.d
Search vendor "Siemens" for product "Desigo Pxc50-e.d"
--
Safe
Siemens
Search vendor "Siemens"
Desigo Pxc64-u Firmware
Search vendor "Siemens" for product "Desigo Pxc64-u Firmware"
>= 2.3 < 6.30.016
Search vendor "Siemens" for product "Desigo Pxc64-u Firmware" and version " >= 2.3 < 6.30.016"
-
Affected
in Siemens
Search vendor "Siemens"
Desigo Pxc64-u
Search vendor "Siemens" for product "Desigo Pxc64-u"
--
Safe
Siemens
Search vendor "Siemens"
Desigo Pxc100-e.d Firmware
Search vendor "Siemens" for product "Desigo Pxc100-e.d Firmware"
>= 2.3 < 6.30.016
Search vendor "Siemens" for product "Desigo Pxc100-e.d Firmware" and version " >= 2.3 < 6.30.016"
-
Affected
in Siemens
Search vendor "Siemens"
Desigo Pxc100-e.d
Search vendor "Siemens" for product "Desigo Pxc100-e.d"
--
Safe
Siemens
Search vendor "Siemens"
Desigo Pxc128-u Firmware
Search vendor "Siemens" for product "Desigo Pxc128-u Firmware"
>= 2.3 < 6.30.016
Search vendor "Siemens" for product "Desigo Pxc128-u Firmware" and version " >= 2.3 < 6.30.016"
-
Affected
in Siemens
Search vendor "Siemens"
Desigo Pxc128-u
Search vendor "Siemens" for product "Desigo Pxc128-u"
--
Safe
Siemens
Search vendor "Siemens"
Desigo Pxc200-e.d Firmware
Search vendor "Siemens" for product "Desigo Pxc200-e.d Firmware"
>= 2.3 < 6.30.016
Search vendor "Siemens" for product "Desigo Pxc200-e.d Firmware" and version " >= 2.3 < 6.30.016"
-
Affected
in Siemens
Search vendor "Siemens"
Desigo Pxc200-e.d
Search vendor "Siemens" for product "Desigo Pxc200-e.d"
--
Safe
Siemens
Search vendor "Siemens"
Desigo Pxm20-e Firmware
Search vendor "Siemens" for product "Desigo Pxm20-e Firmware"
>= 2.3 < 6.30.016
Search vendor "Siemens" for product "Desigo Pxm20-e Firmware" and version " >= 2.3 < 6.30.016"
-
Affected
in Siemens
Search vendor "Siemens"
Desigo Pxm20-e
Search vendor "Siemens" for product "Desigo Pxm20-e"
--
Safe
Siemens
Search vendor "Siemens"
Nucleus Net
Search vendor "Siemens" for product "Nucleus Net"
*-
Affected
Siemens
Search vendor "Siemens"
Nucleus Readystart V3
Search vendor "Siemens" for product "Nucleus Readystart V3"
< 2017.02.4
Search vendor "Siemens" for product "Nucleus Readystart V3" and version " < 2017.02.4"
-
Affected
Siemens
Search vendor "Siemens"
Nucleus Source Code
Search vendor "Siemens" for product "Nucleus Source Code"
*-
Affected