Vulnerability Name:

CVE-2021-25669 (CCN-199902)

Assigned:2021-04-13
Published:2021-04-13
Updated:2022-05-13
Summary:A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < 5.5.1), SCALANCE X201-3P IRT (All versions < 5.5.1), SCALANCE X201-3P IRT PRO (All versions < 5.5.1), SCALANCE X202-2 IRT (All versions < 5.5.1), SCALANCE X202-2P IRT (incl. SIPLUS NET variant) (All versions < 5.5.1), SCALANCE X202-2P IRT PRO (All versions < 5.5.1), SCALANCE X204 IRT (All versions < 5.5.1), SCALANCE X204 IRT PRO (All versions < 5.5.1), SCALANCE X204-2 (incl. SIPLUS NET variant) (All versions < V5.2.5), SCALANCE X204-2FM (All versions < V5.2.5), SCALANCE X204-2LD (incl. SIPLUS NET variant) (All versions < V5.2.5), SCALANCE X204-2LD TS (All versions < V5.2.5), SCALANCE X204-2TS (All versions < V5.2.5), SCALANCE X206-1 (All versions < V5.2.5), SCALANCE X206-1LD (All versions < V5.2.5), SCALANCE X208 (incl. SIPLUS NET variant) (All versions < V5.2.5), SCALANCE X208PRO (All versions < V5.2.5), SCALANCE X212-2 (incl. SIPLUS NET variant) (All versions < V5.2.5), SCALANCE X212-2LD (All versions < V5.2.5), SCALANCE X216 (All versions < V5.2.5), SCALANCE X224 (All versions < V5.2.5), SCALANCE XF201-3P IRT (All versions < 5.5.1), SCALANCE XF202-2P IRT (All versions < 5.5.1), SCALANCE XF204 (All versions < V5.2.5), SCALANCE XF204 IRT (All versions < 5.5.1), SCALANCE XF204-2 (incl. SIPLUS NET variant) (All versions < V5.2.5), SCALANCE XF204-2BA IRT (All versions < 5.5.1), SCALANCE XF206-1 (All versions < V5.2.5), SCALANCE XF208 (All versions < V5.2.5). Incorrect processing of POST requests in the web server may write out of bounds in stack. An attacker might leverage this to denial-of-service of the device or remote code execution.
CVSS v3 Severity:9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
9.8 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.5 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
10.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-121
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2021-25669

Source: MISC
Type: Patch, Vendor Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-187092.pdf

Source: CCN
Type: Siemens Security Advisory SSA-187092
Several Buffer-Overflow Vulnerabilities in Web Server of SCALANCE X-200

Source: XF
Type: UNKNOWN
siemens-cve202125669-bo(199902)

Source: CCN
Type: ICSA-21-103-07
Siemens Web Server of SCALANCE X200

Vulnerable Configuration:Configuration 1:
  • cpe:/o:siemens:scalance_x200-4p_irt_firmware:*:*:*:*:*:*:*:* (Version < 5.5.1)
  • AND
  • cpe:/h:siemens:scalance_x200-4p_irt:-:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:siemens:scalance_x201-3p_irt_firmware:*:*:*:*:*:*:*:* (Version < 5.5.1)
  • AND
  • cpe:/h:siemens:scalance_x201-3p_irt:-:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:siemens:scalance_x201-3p_irt_pro_firmware:*:*:*:*:*:*:*:* (Version < 5.5.1)
  • AND
  • cpe:/h:siemens:scalance_x201-3p_irt_pro:-:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:siemens:scalance_x202-2pirt_firmware:*:*:*:*:*:*:*:* (Version < 5.5.1)
  • AND
  • cpe:/h:siemens:scalance_x202-2_irt:-:*:*:*:*:*:*:*

  • Configuration 5:
  • cpe:/o:siemens:scalance_x202-2p_irt_pro_firmware:*:*:*:*:*:*:*:* (Version < 5.5.1)
  • AND
  • cpe:/h:siemens:scalance_x202-2p_irt_pro:-:*:*:*:*:*:*:*

  • Configuration 6:
  • cpe:/o:siemens:scalance_x204_irt_firmware:*:*:*:*:*:*:*:* (Version < 5.5.1)
  • AND
  • cpe:/h:siemens:scalance_x204_irt:-:*:*:*:*:*:*:*

  • Configuration 7:
  • cpe:/o:siemens:scalance_x204_irt_pro_firmware:*:*:*:*:*:*:*:* (Version < 5.5.1)
  • AND
  • cpe:/h:siemens:scalance_x204_irt_pro:-:*:*:*:*:*:*:*

  • Configuration 8:
  • cpe:/o:siemens:scalance_x204-2_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)
  • AND
  • cpe:/h:siemens:scalance_x204-2:-:*:*:*:*:*:*:*

  • Configuration 9:
  • cpe:/o:siemens:scalance_x204-2fm_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)
  • AND
  • cpe:/h:siemens:scalance_x204-2fm:-:*:*:*:*:*:*:*

  • Configuration 10:
  • cpe:/o:siemens:scalance_x204-2ld_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)
  • AND
  • cpe:/h:siemens:scalance_x204-2ld:-:*:*:*:*:*:*:*

  • Configuration 11:
  • cpe:/o:siemens:scalance_x204-2ld_ts_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)
  • AND
  • cpe:/h:siemens:scalance_x204-2ld_ts:-:*:*:*:*:*:*:*

  • Configuration 12:
  • cpe:/o:siemens:scalance_x204-2ts_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)
  • AND
  • cpe:/h:siemens:scalance_x204-2ts:-:*:*:*:*:*:*:*

  • Configuration 13:
  • cpe:/o:siemens:scalance_x206-1_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)
  • AND
  • cpe:/h:siemens:scalance_x206-1:-:*:*:*:*:*:*:*

  • Configuration 14:
  • cpe:/o:siemens:scalance_x206-1ld_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)
  • AND
  • cpe:/h:siemens:scalance_x206-1ld:-:*:*:*:*:*:*:*

  • Configuration 15:
  • cpe:/o:siemens:scalance_x208_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)
  • AND
  • cpe:/h:siemens:scalance_x208:-:*:*:*:*:*:*:*

  • Configuration 16:
  • cpe:/o:siemens:scalance_x208pro_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)
  • AND
  • cpe:/h:siemens:scalance_x208pro:-:*:*:*:*:*:*:*

  • Configuration 17:
  • cpe:/o:siemens:scalance_x212-2_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)
  • AND
  • cpe:/h:siemens:scalance_x212-2:-:*:*:*:*:*:*:*

  • Configuration 18:
  • cpe:/o:siemens:scalance_x212-2ld_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)
  • AND
  • cpe:/h:siemens:scalance_x212-2ld:-:*:*:*:*:*:*:*

  • Configuration 19:
  • cpe:/o:siemens:scalance_x216_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)
  • AND
  • cpe:/h:siemens:scalance_x216:-:*:*:*:*:*:*:*

  • Configuration 20:
  • cpe:/o:siemens:scalance_x224_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)
  • AND
  • cpe:/h:siemens:scalance_x224:-:*:*:*:*:*:*:*

  • Configuration 21:
  • cpe:/o:siemens:scalance_xf201-3p_irt_firmware:*:*:*:*:*:*:*:* (Version < 5.5.1)
  • AND
  • cpe:/h:siemens:scalance_xf201-3p_irt:-:*:*:*:*:*:*:*

  • Configuration 22:
  • cpe:/o:siemens:scalance_xf202-2p_irt_firmware:*:*:*:*:*:*:*:* (Version < 5.5.1)
  • AND
  • cpe:/h:siemens:scalance_xf202-2p_irt:-:*:*:*:*:*:*:*

  • Configuration 23:
  • cpe:/o:siemens:scalance_xf204_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)
  • AND
  • cpe:/h:siemens:scalance_xf204:-:*:*:*:*:*:*:*

  • Configuration 24:
  • cpe:/o:siemens:scalance_xf204_irt_firmware:*:*:*:*:*:*:*:* (Version < 5.5.1)
  • AND
  • cpe:/h:siemens:scalance_xf204_irt:-:*:*:*:*:*:*:*

  • Configuration 25:
  • cpe:/o:siemens:scalance_xf204-2_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)
  • AND
  • cpe:/h:siemens:scalance_xf204-2:-:*:*:*:*:*:*:*

  • Configuration 26:
  • cpe:/o:siemens:scalance_xf204-2ba_irt_firmware:*:*:*:*:*:*:*:* (Version < 5.5.1)
  • AND
  • cpe:/h:siemens:scalance_xf204-2ba_irt:-:*:*:*:*:*:*:*

  • Configuration 27:
  • cpe:/o:siemens:scalance_xf206-1_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)
  • AND
  • cpe:/h:siemens:scalance_xf206-1:-:*:*:*:*:*:*:*

  • Configuration 28:
  • cpe:/o:siemens:scalance_xf208_firmware:*:*:*:*:*:*:*:* (Version < 5.2.5)
  • AND
  • cpe:/h:siemens:scalance_xf208:-:*:*:*:*:*:*:*

  • Configuration 29:
  • cpe:/o:siemens:scalance_x202-2p_irt_firmware:*:*:*:*:*:*:*:* (Version < 5.5.1)
  • AND
  • cpe:/h:siemens:scalance_x202-2p_irt:-:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:siemens:scalance_x200-4p_irt_firmware:5.5.1:*:*:*:*:*:*:*
  • OR cpe:/o:siemens:scalance_x201-3p_irt_firmware:5.5.1:*:*:*:*:*:*:*
  • OR cpe:/o:siemens:scalance_x201-3p_irt_pro_firmware:5.5.1:*:*:*:*:*:*:*
  • OR cpe:/o:siemens:scalance_x202-2_irt_firmware:5.5.1:*:*:*:*:*:*:*
  • OR cpe:/o:siemens:scalance_x202-2p_irt_pro_firmware:5.5.1:*:*:*:*:*:*:*
  • OR cpe:/o:siemens:scalance_x204_irt_firmware:5.5.1:*:*:*:*:*:*:*
  • OR cpe:/o:siemens:scalance_xf201-3p_irt_firmware:5.5.1:*:*:*:*:*:*:*
  • OR cpe:/o:siemens:scalance_xf202-2p_irt_firmware:5.5.1:*:*:*:*:*:*:*
  • OR cpe:/o:siemens:scalance_xf204_irt_firmware:5.5.1:*:*:*:*:*:*:*
  • OR cpe:/o:siemens:scalance_xf204-2ba_irt_firmware:5.5.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    siemens scalance x200-4p irt firmware *
    siemens scalance x200-4p irt -
    siemens scalance x201-3p irt firmware *
    siemens scalance x201-3p irt -
    siemens scalance x201-3p irt pro firmware *
    siemens scalance x201-3p irt pro -
    siemens scalance x202-2pirt firmware *
    siemens scalance x202-2 irt -
    siemens scalance x202-2p irt pro firmware *
    siemens scalance x202-2p irt pro -
    siemens scalance x204 irt firmware *
    siemens scalance x204 irt -
    siemens scalance x204 irt pro firmware *
    siemens scalance x204 irt pro -
    siemens scalance x204-2 firmware *
    siemens scalance x204-2 -
    siemens scalance x204-2fm firmware *
    siemens scalance x204-2fm -
    siemens scalance x204-2ld firmware *
    siemens scalance x204-2ld -
    siemens scalance x204-2ld ts firmware *
    siemens scalance x204-2ld ts -
    siemens scalance x204-2ts firmware *
    siemens scalance x204-2ts -
    siemens scalance x206-1 firmware *
    siemens scalance x206-1 -
    siemens scalance x206-1ld firmware *
    siemens scalance x206-1ld -
    siemens scalance x208 firmware *
    siemens scalance x208 -
    siemens scalance x208pro firmware *
    siemens scalance x208pro -
    siemens scalance x212-2 firmware *
    siemens scalance x212-2 -
    siemens scalance x212-2ld firmware *
    siemens scalance x212-2ld -
    siemens scalance x216 firmware *
    siemens scalance x216 -
    siemens scalance x224 firmware *
    siemens scalance x224 -
    siemens scalance xf201-3p irt firmware *
    siemens scalance xf201-3p irt -
    siemens scalance xf202-2p irt firmware *
    siemens scalance xf202-2p irt -
    siemens scalance xf204 firmware *
    siemens scalance xf204 -
    siemens scalance xf204 irt firmware *
    siemens scalance xf204 irt -
    siemens scalance xf204-2 firmware *
    siemens scalance xf204-2 -
    siemens scalance xf204-2ba irt firmware *
    siemens scalance xf204-2ba irt -
    siemens scalance xf206-1 firmware *
    siemens scalance xf206-1 -
    siemens scalance xf208 firmware *
    siemens scalance xf208 -
    siemens scalance x202-2p irt firmware *
    siemens scalance x202-2p irt -
    siemens scalance x200-4p irt firmware 5.5.1
    siemens scalance x201-3p irt firmware 5.5.1
    siemens scalance x201-3p irt pro firmware 5.5.1
    siemens scalance x202-2 irt firmware 5.5.1
    siemens scalance x202-2p irt pro firmware 5.5.1
    siemens scalance x204 irt firmware 5.5.1
    siemens scalance xf201-3p irt firmware 5.5.1
    siemens scalance xf202-2p irt firmware 5.5.1
    siemens scalance xf204 irt firmware 5.5.1
    siemens scalance xf204-2ba irt firmware 5.5.1