CVE Database
/

CVE-2021-31884

Back to search

CVE-2021-31884

Published: Nov 9, 2021

Modified: Aug 3, 2024

PUBLISHED

Description

A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions < V3.5.4), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.19), APOGEE PXC Modular (BACnet) (All versions < V3.5.4), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.19), Capital VSTAR (All versions with enabled Ethernet options), Desigo PXC00-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC00-U (All versions >= V2.3 and < V6.30.016), Desigo PXC001-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC100-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC12-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC128-U (All versions >= V2.3 and < V6.30.016), Desigo PXC200-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC22-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC22.1-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC36.1-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC50-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC64-U (All versions >= V2.3 and < V6.30.016), Desigo PXM20-E (All versions >= V2.3 and < V6.30.016), Nucleus NET (All versions), Nucleus ReadyStart V3 (All versions < V2017.02.4), Nucleus Source Code (All versions), TALON TC Compact (BACnet) (All versions < V3.5.4), TALON TC Modular (BACnet) (All versions < V3.5.4). The DHCP client application assumes that the data supplied with the “Hostname” DHCP option is NULL terminated. In cases when global hostname variable is not defined, this may lead to Out-of-bound reads, writes, and Denial-of-service conditions. (FSMD-2021-0014)

VendorProductVersions

Siemens

APOGEE MBC (PPC) (BACnet)

affected
All versions

Siemens

APOGEE MBC (PPC) (P2 Ethernet)

affected
All versions

Siemens

APOGEE MEC (PPC) (BACnet)

affected
All versions

Siemens

APOGEE MEC (PPC) (P2 Ethernet)

affected
All versions

Siemens

APOGEE PXC Compact (BACnet)

affected
All versions < V3.5.4

Siemens

APOGEE PXC Compact (P2 Ethernet)

affected
All versions < V2.8.19

Siemens

APOGEE PXC Modular (BACnet)

affected
All versions < V3.5.4

Siemens

APOGEE PXC Modular (P2 Ethernet)

affected
All versions < V2.8.19

Siemens

Capital VSTAR

affected
All versions with enabled Ethernet options

Siemens

Desigo PXC00-E.D

affected
All versions >= V2.3 and < V6.30.016

Siemens

Desigo PXC00-U

affected
All versions >= V2.3 and < V6.30.016

Siemens

Desigo PXC001-E.D

affected
All versions >= V2.3 and < V6.30.016

Siemens

Desigo PXC100-E.D

affected
All versions >= V2.3 and < V6.30.016

Siemens

Desigo PXC12-E.D

affected
All versions >= V2.3 and < V6.30.016

Siemens

Desigo PXC128-U

affected
All versions >= V2.3 and < V6.30.016

Siemens

Desigo PXC200-E.D

affected
All versions >= V2.3 and < V6.30.016

Siemens

Desigo PXC22-E.D

affected
All versions >= V2.3 and < V6.30.016

Siemens

Desigo PXC22.1-E.D

affected
All versions >= V2.3 and < V6.30.016

Siemens

Desigo PXC36.1-E.D

affected
All versions >= V2.3 and < V6.30.016

Siemens

Desigo PXC50-E.D

affected
All versions >= V2.3 and < V6.30.016

Siemens

Desigo PXC64-U

affected
All versions >= V2.3 and < V6.30.016

Siemens

Desigo PXM20-E

affected
All versions >= V2.3 and < V6.30.016

Siemens

Nucleus NET

affected
All versions

Siemens

Nucleus ReadyStart V3

affected
All versions < V2017.02.4

Siemens

Nucleus Source Code

affected
All versions

Siemens

TALON TC Compact (BACnet)

affected
All versions < V3.5.4

Siemens

TALON TC Modular (BACnet)

affected
All versions < V3.5.4

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now