// For flags

CVE-2021-37186

 

Severity Score

5.4
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A vulnerability has been identified in LOGO! CMR2020 (All versions < V2.2), LOGO! CMR2040 (All versions < V2.2), SIMATIC RTU3010C (All versions < V4.0.9), SIMATIC RTU3030C (All versions < V4.0.9), SIMATIC RTU3031C (All versions < V4.0.9), SIMATIC RTU3041C (All versions < V4.0.9). The underlying TCP/IP stack does not properly calculate the random numbers used as ISN (Initial Sequence Numbers). An adjacent attacker with network access to the LAN interface could interfere with traffic, spoof the connection and gain access to sensitive information.

Se ha identificado una vulnerabilidad en LOGO! CMR2020 (Todas las versiones anteriores a la versión V2.2), LOGO! CMR2040 (Todas las versiones anteriores a la versión V2.2), SIMATIC RTU3010C (Todas las versiones anteriores a la versión V4.0.9), SIMATIC RTU3030C (Todas las versiones anteriores a la versión V4.0.9), SIMATIC RTU3031C (Todas las versiones anteriores a la versión V4.0.9), SIMATIC RTU3041C (Todas las versiones anteriores a la versión V4.0.9). La pila TCP/IP subyacente no calcula apropiadamente los números aleatorios usados como ISN (Initial Sequence Numbers). Un atacante adyacente con acceso a la red de la interfaz LAN podría interferir en el tráfico, falsear la conexión y conseguir acceso a información confidencial

*Credits: N/A
CVSS Scores
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Adjacent
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-07-21 CVE Reserved
  • 2021-09-14 CVE Published
  • 2024-05-30 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-330: Use of Insufficiently Random Values
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Siemens
Search vendor "Siemens"
Logo\! Cmr2020 Firmware
Search vendor "Siemens" for product "Logo\! Cmr2020 Firmware"
< 2.2
Search vendor "Siemens" for product "Logo\! Cmr2020 Firmware" and version " < 2.2"
-
Affected
in Siemens
Search vendor "Siemens"
Logo\! Cmr2020
Search vendor "Siemens" for product "Logo\! Cmr2020"
--
Safe
Siemens
Search vendor "Siemens"
Logo\! Cmr2040 Firmware
Search vendor "Siemens" for product "Logo\! Cmr2040 Firmware"
< 2.2
Search vendor "Siemens" for product "Logo\! Cmr2040 Firmware" and version " < 2.2"
-
Affected
in Siemens
Search vendor "Siemens"
Logo\! Cmr2040
Search vendor "Siemens" for product "Logo\! Cmr2040"
--
Safe
Siemens
Search vendor "Siemens"
Simatic Rtu3010c Firmware
Search vendor "Siemens" for product "Simatic Rtu3010c Firmware"
< 4.0.9
Search vendor "Siemens" for product "Simatic Rtu3010c Firmware" and version " < 4.0.9"
-
Affected
in Siemens
Search vendor "Siemens"
Simatic Rtu3010c
Search vendor "Siemens" for product "Simatic Rtu3010c"
*-
Safe
Siemens
Search vendor "Siemens"
Simatic Rtu3030c Firmware
Search vendor "Siemens" for product "Simatic Rtu3030c Firmware"
< 4.0.9
Search vendor "Siemens" for product "Simatic Rtu3030c Firmware" and version " < 4.0.9"
-
Affected
in Siemens
Search vendor "Siemens"
Simatic Rtu3030c
Search vendor "Siemens" for product "Simatic Rtu3030c"
*-
Safe
Siemens
Search vendor "Siemens"
Simatic Rtu3031c Firmware
Search vendor "Siemens" for product "Simatic Rtu3031c Firmware"
< 4.0.9
Search vendor "Siemens" for product "Simatic Rtu3031c Firmware" and version " < 4.0.9"
-
Affected
in Siemens
Search vendor "Siemens"
Simatic Rtu3031c
Search vendor "Siemens" for product "Simatic Rtu3031c"
*-
Safe
Siemens
Search vendor "Siemens"
Simatic Rtu3041c Firmware
Search vendor "Siemens" for product "Simatic Rtu3041c Firmware"
< 4.0.9
Search vendor "Siemens" for product "Simatic Rtu3041c Firmware" and version " < 4.0.9"
-
Affected
in Siemens
Search vendor "Siemens"
Simatic Rtu3041c
Search vendor "Siemens" for product "Simatic Rtu3041c"
*-
Safe