PT-2021-7731 · Siemens · Scalance X201-3P Irt+20

Published

2021-04-13

·

Updated

2022-05-01

·

CVE-2021-25668

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SCALANCE X200-4P IRT versions prior to 5.5.1 SCALANCE X201-3P IRT versions prior to 5.5.1 SCALANCE X201-3P IRT PRO versions prior to 5.5.1 SCALANCE X202-2 IRT versions prior to 5.5.1 SCALANCE X202-2P IRT versions prior to 5.5.1 SCALANCE X202-2P IRT PRO versions prior to 5.5.1 SCALANCE X204 IRT versions prior to 5.5.1 SCALANCE X204 IRT PRO versions prior to 5.5.1 SCALANCE X204 versions prior to V5.2.5 SCALANCE X204-2FM versions prior to V5.2.5 SCALANCE X204-2LD versions prior to V5.2.5 SCALANCE X204-2LD TS versions prior to V5.2.5 SCALANCE X204-2TS versions prior to V5.2.5 SCALANCE X206-1 versions prior to V5.2.5 SCALANCE X206-1LD versions prior to V5.2.5 SCALANCE X208 versions prior to V5.2.5 SCALANCE X208PRO versions prior to V5.2.5 SCALANCE X212-2 versions prior to V5.2.5 SCALANCE X212-2LD versions prior to V5.2.5 SCALANCE X216 versions prior to V5.2.5 SCALANCE X224 versions prior to V5.2.5 SCALANCE XF201-3P IRT versions prior to 5.5.1 SCALANCE XF202-2P IRT versions prior to 5.5.1 SCALANCE XF204 versions prior to V5.2.5 SCALANCE XF204 IRT versions prior to 5.5.1 SCALANCE XF204-2 versions prior to V5.2.5 SCALANCE XF204-2BA IRT versions prior to 5.5.1 SCALANCE XF206-1 versions prior to V5.2.5 SCALANCE XF208 versions prior to V5.2.5
Description The issue is related to incorrect processing of POST requests in the webserver, which may result in write out of bounds in heap. This could allow an attacker to cause denial-of-service on the device and potentially execute code remotely.
Recommendations For SCALANCE X200-4P IRT versions prior to 5.5.1, update to version 5.5.1 or later. For SCALANCE X201-3P IRT versions prior to 5.5.1, update to version 5.5.1 or later. For SCALANCE X201-3P IRT PRO versions prior to 5.5.1, update to version 5.5.1 or later. For SCALANCE X202-2 IRT versions prior to 5.5.1, update to version 5.5.1 or later. For SCALANCE X202-2P IRT versions prior to 5.5.1, update to version 5.5.1 or later. For SCALANCE X202-2P IRT PRO versions prior to 5.5.1, update to version 5.5.1 or later. For SCALANCE X204 IRT versions prior to 5.5.1, update to version 5.5.1 or later. For SCALANCE X204 IRT PRO versions prior to 5.5.1, update to version 5.5.1 or later. For SCALANCE X204 versions prior to V5.2.5, update to version V5.2.5 or later. For SCALANCE X204-2FM versions prior to V5.2.5, update to version V5.2.5 or later. For SCALANCE X204-2LD versions prior to V5.2.5, update to version V5.2.5 or later. For SCALANCE X204-2LD TS versions prior to V5.2.5, update to version V5.2.5 or later. For SCALANCE X204-2TS versions prior to V5.2.5, update to version V5.2.5 or later. For SCALANCE X206-1 versions prior to V5.2.5, update to version V5.2.5 or later. For SCALANCE X206-1LD versions prior to V5.2.5, update to version V5.2.5 or later. For SCALANCE X208 versions prior to V5.2.5, update to version V5.2.5 or later. For SCALANCE X208PRO versions prior to V5.2.5, update to version V5.2.5 or later. For SCALANCE X212-2 versions prior to V5.2.5, update to version V5.2.5 or later. For SCALANCE X212-2LD versions prior to V5.2.5, update to version V5.2.5 or later. For SCALANCE X216 versions prior to V5.2.5, update to version V5.2.5 or later. For SCALANCE X224 versions prior to V5.2.5, update to version V5.2.5 or later. For SCALANCE XF201-3P IRT versions prior to 5.5.1, update to version 5.5.1 or later. For SCALANCE XF202-2P IRT versions prior to 5.5.1, update to version 5.5.1 or later. For SCALANCE XF204 versions prior to V5.2.5, update to version V5.2.5 or later. For SCALANCE XF204 IRT versions prior to 5.5.1, update to version 5.5.1 or later. For SCALANCE XF204-2 versions prior to V5.2.5, update to version V5.2.5 or later. For SCALANCE XF204-2BA IRT versions prior to 5.5.1, update to version 5.5.1 or later. For SCALANCE XF206-1 versions prior to V5.2.5, update to version V5.2.5 or later. For SCALANCE XF208 versions prior to V5.2.5, update to version V5.2.5 or later.

Fix

Heap Based Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-02053
CVE-2021-25668

Affected Products

Scalance X200-4P Irt
Scalance X201-3P Irt
Scalance X201-3P Irt Pro
Scalance X202-2P Irt
Scalance Xf204
Scalance X204Irt
Scalance X204Irt Pro
Scalance X204-2Fm
Scalance X204-2Ld
Scalance X204-2Ld Ts
Scalance X204-2Ts
Scalance X206-1Ld
Scalance X208
Scalance X208Pro
Scalance X212-2Ld
Scalance X216
Scalance X224
Scalance Xf204-2
Scalance Xf204-2Ba Irt
Scalance Xf206-1
Scalance Xf208