PT-2021-16739 · Mentor Graphics · Nucleus Source Code+3
Published
2021-04-22
·
Updated
2024-02-13
·
CVE-2021-25664
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Capital Embedded AR Classic 431-422 versions all
Capital Embedded AR Classic R20-11 versions prior to V2303
Nucleus NET versions all
Nucleus ReadyStart V3 versions prior to V2017.02.4
Nucleus ReadyStart V4 versions prior to V4.1.0
Nucleus Source Code versions all
Description
A vulnerability has been identified in the processing of the Hop-by-Hop extension header in IPv6 packets. The function that handles this header and its options lacks checks against the length field, allowing attackers to cause the function to enter an infinite loop by providing arbitrary length values.
Recommendations
For Capital Embedded AR Classic 431-422, update to a version that includes a fix for this issue.
For Capital Embedded AR Classic R20-11, update to version V2303 or later.
For Nucleus NET, consider temporarily disabling the processing of IPv6 packets until a patch is available.
For Nucleus ReadyStart V3, update to version V2017.02.4 or later.
For Nucleus ReadyStart V4, update to version V4.1.0 or later.
For Nucleus Source Code, restrict the use of the affected IPv6 stack until a fix is implemented.
Fix
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Capital Embedded Ar Classic
Nucleus Net
Nucleus Readystart
Nucleus Source Code