| Vulnerability Name: | CVE-2021-31340 (CCN-203283) |
| Assigned: | 2021-06-08 |
| Published: | 2021-06-08 |
| Updated: | 2022-10-06 |
| Summary: | A vulnerability has been identified in SIMATIC RF166C (All versions > V1.1 and < V1.3.2), SIMATIC RF185C (All versions > V1.1 and < V1.3.2), SIMATIC RF186C (All versions > V1.1 and < V1.3.2), SIMATIC RF186CI (All versions > V1.1 and < V1.3.2), SIMATIC RF188C (All versions > V1.1 and < V1.3.2), SIMATIC RF188CI (All versions > V1.1 and < V1.3.2), SIMATIC RF360R (All versions < V2.0), SIMATIC Reader RF610R CMIIT (All versions > V3.0 < V4.0), SIMATIC Reader RF610R ETSI (All versions > V3.0 < V4.0), SIMATIC Reader RF610R FCC (All versions > V3.0 < V4.0), SIMATIC Reader RF615R CMIIT (All versions > V3.0 < V4.0), SIMATIC Reader RF615R ETSI (All versions > V3.0 < V4.0), SIMATIC Reader RF615R FCC (All versions > V3.0 < V4.0), SIMATIC Reader RF650R ARIB (All versions > V3.0 < V4.0), SIMATIC Reader RF650R CMIIT (All versions > V3.0 < V4.0), SIMATIC Reader RF650R ETSI (All versions > V3.0 < V4.0), SIMATIC Reader RF650R FCC (All versions > V3.0 < V4.0), SIMATIC Reader RF680R ARIB (All versions > V3.0 < V4.0), SIMATIC Reader RF680R CMIIT (All versions > V3.0 < V4.0), SIMATIC Reader RF680R ETSI (All versions > V3.0 < V4.0), SIMATIC Reader RF680R FCC (All versions > V3.0 < V4.0), SIMATIC Reader RF685R ARIB (All versions > V3.0 < V4.0), SIMATIC Reader RF685R CMIIT (All versions > V3.0 < V4.0), SIMATIC Reader RF685R ETSI (All versions > V3.0 < V4.0), SIMATIC Reader RF685R FCC (All versions > V3.0 < V4.0). Affected devices do not properly handle large numbers of incoming connections. An attacker may leverage this to cause a Denial-of-Service situation.
|
| CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)| Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | | Scope: | Scope (S): Unchanged
| | Impact Metrics: | Confidentiality (C): None Integrity (I): None Availibility (A): High | 7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) 6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)| Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | | Scope: | Scope (S): Unchanged
| | Impact Metrics: | Confidentiality (C): None Integrity (I): None Availibility (A): High |
|
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)| Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Authentication (Au): None | | Impact Metrics: | Confidentiality (C): None Integrity (I): None Availibility (A): Partial | 7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)| Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Athentication (Au): None
| | Impact Metrics: | Confidentiality (C): None Integrity (I): None Availibility (A): Complete |
|
| Vulnerability Type: | CWE-400 CWE-400
|
| Vulnerability Consequences: | Denial of Service |
| References: | Source: MITRE Type: CNA CVE-2021-31340
Source: MISC Type: Mitigation, Patch, Vendor Advisory https://cert-portal.siemens.com/productcert/pdf/ssa-787292.pdf
Source: CCN Type: Siemens Security Advisory SSA-787292 Denial-of-Service Vulnerability in SIMATIC RFID Readers
Source: XF Type: UNKNOWN simatic-cve202131340-dos(203283)
Source: CCN Type: ICSA-21-159-13 Siemens SIMATIC RFID
|
| Vulnerable Configuration: | Configuration 1: cpe:/o:siemens:simatic_rf166c_firmware:*:*:*:*:*:*:*:* (Version > 1.1 and < 1.3.2)AND cpe:/h:siemens:simatic_rf166c:-:*:*:*:*:*:*:* Configuration 2: cpe:/o:siemens:simatic_rf185c_firmware:*:*:*:*:*:*:*:* (Version > 1.1 and < 1.3.2)AND cpe:/h:siemens:simatic_rf185c:-:*:*:*:*:*:*:* Configuration 3: cpe:/o:siemens:simatic_rf186c_firmware:*:*:*:*:*:*:*:* (Version > 1.1 and < 1.3.2)AND cpe:/h:siemens:simatic_rf186c:-:*:*:*:*:*:*:* Configuration 4: cpe:/o:siemens:simatic_rf186ci_firmware:*:*:*:*:*:*:*:* (Version > 1.1 and < 1.3.2)AND cpe:/h:siemens:simatic_rf186ci:-:*:*:*:*:*:*:* Configuration 5: cpe:/o:siemens:simatic_rf188c_firmware:*:*:*:*:*:*:*:* (Version > 1.1 and < 1.3.2)AND cpe:/h:siemens:simatic_rf188c:-:*:*:*:*:*:*:* Configuration 6: cpe:/o:siemens:simatic_rf188ci_firmware:*:*:*:*:*:*:*:* (Version > 1.1 and < 1.3.2)AND cpe:/h:siemens:simatic_rf188ci:-:*:*:*:*:*:*:* Configuration 7: cpe:/o:siemens:simatic_rf360r_firmware:*:*:*:*:*:*:*:* (Version < 2.0)AND cpe:/h:siemens:simatic_rf360r:-:*:*:*:*:*:*:* Configuration 8: cpe:/o:siemens:simatic_reader_rf610r_cmiit_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)AND cpe:/h:siemens:simatic_reader_rf610r_cmiit:-:*:*:*:*:*:*:* Configuration 9: cpe:/o:siemens:simatic_reader_rf610r_etsi_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)AND cpe:/h:siemens:simatic_reader_rf610r_etsi:-:*:*:*:*:*:*:* Configuration 10: cpe:/o:siemens:simatic_reader_rf610r_fcc_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)AND cpe:/h:siemens:simatic_reader_rf610r_fcc:-:*:*:*:*:*:*:* Configuration 11: cpe:/o:siemens:simatic_reader_rf615r_cmiit_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)AND cpe:/h:siemens:simatic_reader_rf615r_cmiit:-:*:*:*:*:*:*:* Configuration 12: cpe:/o:siemens:simatic_reader_rf615r_etsi_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)AND cpe:/h:siemens:simatic_reader_rf615r_etsi:-:*:*:*:*:*:*:* Configuration 13: cpe:/o:siemens:simatic_reader_rf615r_fcc_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)AND cpe:/h:siemens:simatic_reader_rf615r_fcc:-:*:*:*:*:*:*:* Configuration 14: cpe:/o:siemens:simatic_reader_rf650r_cmiit_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)AND cpe:/h:siemens:simatic_reader_rf650r_cmiit:-:*:*:*:*:*:*:* Configuration 15: cpe:/o:siemens:simatic_reader_rf650r_etsi_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)AND cpe:/h:siemens:simatic_reader_rf650r_etsi:-:*:*:*:*:*:*:* Configuration 16: cpe:/o:siemens:simatic_reader_rf650r_fcc_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)AND cpe:/h:siemens:simatic_reader_rf650r_fcc:-:*:*:*:*:*:*:* Configuration 17: cpe:/o:siemens:simatic_reader_rf650r_arib_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)AND cpe:/h:siemens:simatic_reader_rf650r_arib:-:*:*:*:*:*:*:* Configuration 18: cpe:/o:siemens:simatic_reader_rf680r_cmiit_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)AND cpe:/h:siemens:simatic_reader_rf680r_cmiit:-:*:*:*:*:*:*:* Configuration 19: cpe:/o:siemens:simatic_reader_rf680r_etsi_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)AND cpe:/h:siemens:simatic_reader_rf680r_etsi:-:*:*:*:*:*:*:* Configuration 20: cpe:/o:siemens:simatic_reader_rf680r_fcc_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)AND cpe:/h:siemens:simatic_reader_rf680r_fcc:-:*:*:*:*:*:*:* Configuration 21: cpe:/o:siemens:simatic_reader_rf680r_arib_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)AND cpe:/h:siemens:simatic_reader_rf680r_arib:-:*:*:*:*:*:*:* Configuration 22: cpe:/o:siemens:simatic_reader_rf685r_cmiit_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)AND cpe:/h:siemens:simatic_reader_rf685r_cmiit:-:*:*:*:*:*:*:* Configuration 23: cpe:/o:siemens:simatic_reader_rf685r_etsi_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)AND cpe:/h:siemens:simatic_reader_rf685r_etsi:-:*:*:*:*:*:*:* Configuration 24: cpe:/o:siemens:simatic_reader_rf685r_fcc_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)AND cpe:/h:siemens:simatic_reader_rf685r_fcc:-:*:*:*:*:*:*:* Configuration 25: cpe:/o:siemens:simatic_reader_rf685r_arib_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)AND cpe:/h:siemens:simatic_reader_rf685r_arib:-:*:*:*:*:*:*:* Configuration CCN 1: cpe:/o:siemens:simatic_rf166c_firmware:1.3.2:*:*:*:*:*:*:*OR cpe:/o:siemens:simatic_rf188ci_firmware:1.3.2:*:*:*:*:*:*:*OR cpe:/o:siemens:simatic_rf680r_firmware:3.0:*:*:*:*:*:*:*OR cpe:/o:siemens:simatic_rf685r_firmware:3.0:*:*:*:*:*:*:*
Denotes that component is vulnerable |
| BACK |
siemens simatic rf166c firmware *
siemens simatic rf166c -
siemens simatic rf185c firmware *
siemens simatic rf185c -
siemens simatic rf186c firmware *
siemens simatic rf186c -
siemens simatic rf186ci firmware *
siemens simatic rf186ci -
siemens simatic rf188c firmware *
siemens simatic rf188c -
siemens simatic rf188ci firmware *
siemens simatic rf188ci -
siemens simatic rf360r firmware *
siemens simatic rf360r -
siemens simatic reader rf610r cmiit firmware *
siemens simatic reader rf610r cmiit -
siemens simatic reader rf610r etsi firmware *
siemens simatic reader rf610r etsi -
siemens simatic reader rf610r fcc firmware *
siemens simatic reader rf610r fcc -
siemens simatic reader rf615r cmiit firmware *
siemens simatic reader rf615r cmiit -
siemens simatic reader rf615r etsi firmware *
siemens simatic reader rf615r etsi -
siemens simatic reader rf615r fcc firmware *
siemens simatic reader rf615r fcc -
siemens simatic reader rf650r cmiit firmware *
siemens simatic reader rf650r cmiit -
siemens simatic reader rf650r etsi firmware *
siemens simatic reader rf650r etsi -
siemens simatic reader rf650r fcc firmware *
siemens simatic reader rf650r fcc -
siemens simatic reader rf650r arib firmware *
siemens simatic reader rf650r arib -
siemens simatic reader rf680r cmiit firmware *
siemens simatic reader rf680r cmiit -
siemens simatic reader rf680r etsi firmware *
siemens simatic reader rf680r etsi -
siemens simatic reader rf680r fcc firmware *
siemens simatic reader rf680r fcc -
siemens simatic reader rf680r arib firmware *
siemens simatic reader rf680r arib -
siemens simatic reader rf685r cmiit firmware *
siemens simatic reader rf685r cmiit -
siemens simatic reader rf685r etsi firmware *
siemens simatic reader rf685r etsi -
siemens simatic reader rf685r fcc firmware *
siemens simatic reader rf685r fcc -
siemens simatic reader rf685r arib firmware *
siemens simatic reader rf685r arib -
siemens simatic rf166c firmware 1.3.2
siemens simatic rf188ci firmware 1.3.2
siemens simatic rf680r firmware 3.0
siemens simatic rf685r firmware 3.0