PT-2021-7827 · Unknown · Capital Embedded Ar Classic 431-422+1

Published

2021-11-09

·

Updated

2024-10-08

·

CVE-2021-31881

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Capital Embedded AR Classic 431-422 versions all Capital Embedded AR Classic R20-11 versions prior to V2303
Description A Denial-of-Service condition can occur due to the DHCP client application not validating the length of the Vendor option(s) when processing a DHCP OFFER message. The issue is related to a buffer overflow in memory, which can be exploited by a remote attacker to cause a denial of service.
Recommendations For Capital Embedded AR Classic 431-422, update to a version that includes the fix for this issue. For Capital Embedded AR Classic R20-11 versions prior to V2303, update to version V2303 or later to resolve the issue. As a temporary workaround, consider restricting access to the DHCP client application until a patch is available.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2023-03410
CVE-2021-31881

Affected Products

Capital Embedded Ar Classic 431-422
Capital Embedded Ar Classic R20-11