CVE-2021-37182
Summary
| CVE | CVE-2021-37182 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-06-14 10:15:00 UTC |
| Updated | 2022-06-27 17:40:00 UTC |
| Description | A vulnerability has been identified in SCALANCE XM408-4C (All versions < V6.5), SCALANCE XM408-4C (L3 int.) (All versions < V6.5), SCALANCE XM408-8C (All versions < V6.5), SCALANCE XM408-8C (L3 int.) (All versions < V6.5), SCALANCE XM416-4C (All versions < V6.5), SCALANCE XM416-4C (L3 int.) (All versions < V6.5), SCALANCE XR524-8C, 1x230V (All versions < V6.5), SCALANCE XR524-8C, 1x230V (L3 int.) (All versions < V6.5), SCALANCE XR524-8C, 24V (All versions < V6.5), SCALANCE XR524-8C, 24V (L3 int.) (All versions < V6.5), SCALANCE XR524-8C, 2x230V (All versions < V6.5), SCALANCE XR524-8C, 2x230V (L3 int.) (All versions < V6.5), SCALANCE XR526-8C, 1x230V (All versions < V6.5), SCALANCE XR526-8C, 1x230V (L3 int.) (All versions < V6.5), SCALANCE XR526-8C, 24V (All versions < V6.5), SCALANCE XR526-8C, 24V (L3 int.) (All versions < V6.5), SCALANCE XR526-8C, 2x230V (All versions < V6.5), SCALANCE XR526-8C, 2x230V (L3 int.) (All versions < V6.5), SCALANCE XR528-6M (All versions < V6.5), SCALANCE XR528-6M (2HR2) (All versions < V6.5), SCALANCE XR528-6M (2HR2, L3 int.) (All versions < V6.5), SCALANCE XR528-6M (L3 int.) (All versions < V6.5), SCALANCE XR552-12M (All versions < V6.5), SCALANCE XR552-12M (2HR2) (All versions < V6.5), SCALANCE XR552-12M (2HR2) (All versions < V6.5), SCALANCE XR552-12M (2HR2, L3 int.) (All versions < V6.5). The OSPF protocol implementation in affected devices fails to verify the checksum and length fields in the OSPF LS Update messages. An unauthenticated remote attacker could exploit this vulnerability to cause interruptions in the network by sending specially crafted OSPF packets. Successful exploitation requires OSPF to be enabled on an affected device. |
Risk And Classification
Problem Types: CWE-354
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Siemens | Scalance Xm408-4c | - | All | All | All |
| Operating System | Siemens | Scalance Xm408-4c Firmware | All | All | All | All |
| Hardware | Siemens | Scalance Xm408-4c L3 | - | All | All | All |
| Operating System | Siemens | Scalance Xm408-4c L3 Firmware | All | All | All | All |
| Hardware | Siemens | Scalance Xm408-8c | - | All | All | All |
| Operating System | Siemens | Scalance Xm408-8c Firmware | All | All | All | All |
| Hardware | Siemens | Scalance Xm408-8c L3 | - | All | All | All |
| Operating System | Siemens | Scalance Xm408-8c L3 Firmware | All | All | All | All |
| Hardware | Siemens | Scalance Xm416-4c | - | All | All | All |
| Operating System | Siemens | Scalance Xm416-4c Firmware | All | All | All | All |
| Hardware | Siemens | Scalance Xm416-4c L3 | - | All | All | All |
| Operating System | Siemens | Scalance Xm416-4c L3 Firmware | All | All | All | All |
| Hardware | Siemens | Scalance Xr524-8c | - | All | All | All |
| Hardware | Siemens | Scalance Xr524-8c | - | All | All | All |
| Hardware | Siemens | Scalance Xr524-8c | - | All | All | All |
| Hardware | Siemens | Scalance Xr524-8c | - | All | All | All |
| Operating System | Siemens | Scalance Xr524-8c Firmware | All | All | All | All |
| Operating System | Siemens | Scalance Xr524-8c Firmware | All | All | All | All |
| Operating System | Siemens | Scalance Xr524-8c Firmware | All | All | All | All |
| Operating System | Siemens | Scalance Xr524-8c Firmware | All | All | All | All |
| Hardware | Siemens | Scalance Xr524-8c L3 | - | All | All | All |
| Hardware | Siemens | Scalance Xr524-8c L3 | - | All | All | All |
| Hardware | Siemens | Scalance Xr524-8c L3 | - | All | All | All |
| Hardware | Siemens | Scalance Xr524-8c L3 | - | All | All | All |
| Operating System | Siemens | Scalance Xr524-8c L3 Firmware | All | All | All | All |
| Operating System | Siemens | Scalance Xr524-8c L3 Firmware | All | All | All | All |
| Operating System | Siemens | Scalance Xr524-8c L3 Firmware | All | All | All | All |
| Operating System | Siemens | Scalance Xr524-8c L3 Firmware | All | All | All | All |
| Hardware | Siemens | Scalance Xr526-8c | - | All | All | All |
| Hardware | Siemens | Scalance Xr526-8c | - | All | All | All |
| Hardware | Siemens | Scalance Xr526-8c | - | All | All | All |
| Hardware | Siemens | Scalance Xr526-8c | - | All | All | All |
| Operating System | Siemens | Scalance Xr526-8c Firmware | All | All | All | All |
| Operating System | Siemens | Scalance Xr526-8c Firmware | All | All | All | All |
| Operating System | Siemens | Scalance Xr526-8c Firmware | All | All | All | All |
| Operating System | Siemens | Scalance Xr526-8c Firmware | All | All | All | All |
| Hardware | Siemens | Scalance Xr526-8c L3 | - | All | All | All |
| Hardware | Siemens | Scalance Xr526-8c L3 | - | All | All | All |
| Hardware | Siemens | Scalance Xr526-8c L3 | - | All | All | All |
| Hardware | Siemens | Scalance Xr526-8c L3 | - | All | All | All |
| Operating System | Siemens | Scalance Xr526-8c L3 Firmware | All | All | All | All |
| Operating System | Siemens | Scalance Xr526-8c L3 Firmware | All | All | All | All |
| Operating System | Siemens | Scalance Xr526-8c L3 Firmware | All | All | All | All |
| Operating System | Siemens | Scalance Xr526-8c L3 Firmware | All | All | All | All |
| Hardware | Siemens | Scalance Xr528-6m | - | All | All | All |
| Hardware | Siemens | Scalance Xr528-6m 2hr2 | - | All | All | All |
| Operating System | Siemens | Scalance Xr528-6m 2hr2 Firmware | All | All | All | All |
| Hardware | Siemens | Scalance Xr528-6m 2hr2 L3 | - | All | All | All |
| Operating System | Siemens | Scalance Xr528-6m 2hr2 L3 Firmware | All | All | All | All |
| Operating System | Siemens | Scalance Xr528-6m Firmware | All | All | All | All |
| Hardware | Siemens | Scalance Xr528-6m L3 | - | All | All | All |
| Operating System | Siemens | Scalance Xr528-6m L3 Firmware | All | All | All | All |
| Hardware | Siemens | Scalance Xr552-12m | - | All | All | All |
| Hardware | Siemens | Scalance Xr552-12m 2hr2 | - | All | All | All |
| Operating System | Siemens | Scalance Xr552-12m 2hr2 Firmware | All | All | All | All |
| Hardware | Siemens | Scalance Xr552-12m 2hr2 L3 | - | All | All | All |
| Operating System | Siemens | Scalance Xr552-12m 2hr2 L3 Firmware | All | All | All | All |
| Operating System | Siemens | Scalance Xr552-12m Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| cert-portal.siemens.com/productcert/pdf/ssa-145224.pdf | MISC | cert-portal.siemens.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 591031 Siemens SCALANCE XM-400 and XR-500 Vulnerability (SSA-145224) (ICSA-22-167-10)