Vulnerability Name:

CVE-2021-31340 (CCN-203283)

Assigned:2021-06-08
Published:2021-06-08
Updated:2022-10-06
Summary:A vulnerability has been identified in SIMATIC RF166C (All versions > V1.1 and < V1.3.2), SIMATIC RF185C (All versions > V1.1 and < V1.3.2), SIMATIC RF186C (All versions > V1.1 and < V1.3.2), SIMATIC RF186CI (All versions > V1.1 and < V1.3.2), SIMATIC RF188C (All versions > V1.1 and < V1.3.2), SIMATIC RF188CI (All versions > V1.1 and < V1.3.2), SIMATIC RF360R (All versions < V2.0), SIMATIC Reader RF610R CMIIT (All versions > V3.0 < V4.0), SIMATIC Reader RF610R ETSI (All versions > V3.0 < V4.0), SIMATIC Reader RF610R FCC (All versions > V3.0 < V4.0), SIMATIC Reader RF615R CMIIT (All versions > V3.0 < V4.0), SIMATIC Reader RF615R ETSI (All versions > V3.0 < V4.0), SIMATIC Reader RF615R FCC (All versions > V3.0 < V4.0), SIMATIC Reader RF650R ARIB (All versions > V3.0 < V4.0), SIMATIC Reader RF650R CMIIT (All versions > V3.0 < V4.0), SIMATIC Reader RF650R ETSI (All versions > V3.0 < V4.0), SIMATIC Reader RF650R FCC (All versions > V3.0 < V4.0), SIMATIC Reader RF680R ARIB (All versions > V3.0 < V4.0), SIMATIC Reader RF680R CMIIT (All versions > V3.0 < V4.0), SIMATIC Reader RF680R ETSI (All versions > V3.0 < V4.0), SIMATIC Reader RF680R FCC (All versions > V3.0 < V4.0), SIMATIC Reader RF685R ARIB (All versions > V3.0 < V4.0), SIMATIC Reader RF685R CMIIT (All versions > V3.0 < V4.0), SIMATIC Reader RF685R ETSI (All versions > V3.0 < V4.0), SIMATIC Reader RF685R FCC (All versions > V3.0 < V4.0). Affected devices do not properly handle large numbers of incoming connections. An attacker may leverage this to cause a Denial-of-Service situation.
CVSS v3 Severity:7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-400
CWE-400
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2021-31340

Source: MISC
Type: Mitigation, Patch, Vendor Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-787292.pdf

Source: CCN
Type: Siemens Security Advisory SSA-787292
Denial-of-Service Vulnerability in SIMATIC RFID Readers

Source: XF
Type: UNKNOWN
simatic-cve202131340-dos(203283)

Source: CCN
Type: ICSA-21-159-13
Siemens SIMATIC RFID

Vulnerable Configuration:Configuration 1:
  • cpe:/o:siemens:simatic_rf166c_firmware:*:*:*:*:*:*:*:* (Version > 1.1 and < 1.3.2)
  • AND
  • cpe:/h:siemens:simatic_rf166c:-:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:siemens:simatic_rf185c_firmware:*:*:*:*:*:*:*:* (Version > 1.1 and < 1.3.2)
  • AND
  • cpe:/h:siemens:simatic_rf185c:-:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:siemens:simatic_rf186c_firmware:*:*:*:*:*:*:*:* (Version > 1.1 and < 1.3.2)
  • AND
  • cpe:/h:siemens:simatic_rf186c:-:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:siemens:simatic_rf186ci_firmware:*:*:*:*:*:*:*:* (Version > 1.1 and < 1.3.2)
  • AND
  • cpe:/h:siemens:simatic_rf186ci:-:*:*:*:*:*:*:*

  • Configuration 5:
  • cpe:/o:siemens:simatic_rf188c_firmware:*:*:*:*:*:*:*:* (Version > 1.1 and < 1.3.2)
  • AND
  • cpe:/h:siemens:simatic_rf188c:-:*:*:*:*:*:*:*

  • Configuration 6:
  • cpe:/o:siemens:simatic_rf188ci_firmware:*:*:*:*:*:*:*:* (Version > 1.1 and < 1.3.2)
  • AND
  • cpe:/h:siemens:simatic_rf188ci:-:*:*:*:*:*:*:*

  • Configuration 7:
  • cpe:/o:siemens:simatic_rf360r_firmware:*:*:*:*:*:*:*:* (Version < 2.0)
  • AND
  • cpe:/h:siemens:simatic_rf360r:-:*:*:*:*:*:*:*

  • Configuration 8:
  • cpe:/o:siemens:simatic_reader_rf610r_cmiit_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)
  • AND
  • cpe:/h:siemens:simatic_reader_rf610r_cmiit:-:*:*:*:*:*:*:*

  • Configuration 9:
  • cpe:/o:siemens:simatic_reader_rf610r_etsi_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)
  • AND
  • cpe:/h:siemens:simatic_reader_rf610r_etsi:-:*:*:*:*:*:*:*

  • Configuration 10:
  • cpe:/o:siemens:simatic_reader_rf610r_fcc_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)
  • AND
  • cpe:/h:siemens:simatic_reader_rf610r_fcc:-:*:*:*:*:*:*:*

  • Configuration 11:
  • cpe:/o:siemens:simatic_reader_rf615r_cmiit_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)
  • AND
  • cpe:/h:siemens:simatic_reader_rf615r_cmiit:-:*:*:*:*:*:*:*

  • Configuration 12:
  • cpe:/o:siemens:simatic_reader_rf615r_etsi_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)
  • AND
  • cpe:/h:siemens:simatic_reader_rf615r_etsi:-:*:*:*:*:*:*:*

  • Configuration 13:
  • cpe:/o:siemens:simatic_reader_rf615r_fcc_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)
  • AND
  • cpe:/h:siemens:simatic_reader_rf615r_fcc:-:*:*:*:*:*:*:*

  • Configuration 14:
  • cpe:/o:siemens:simatic_reader_rf650r_cmiit_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)
  • AND
  • cpe:/h:siemens:simatic_reader_rf650r_cmiit:-:*:*:*:*:*:*:*

  • Configuration 15:
  • cpe:/o:siemens:simatic_reader_rf650r_etsi_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)
  • AND
  • cpe:/h:siemens:simatic_reader_rf650r_etsi:-:*:*:*:*:*:*:*

  • Configuration 16:
  • cpe:/o:siemens:simatic_reader_rf650r_fcc_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)
  • AND
  • cpe:/h:siemens:simatic_reader_rf650r_fcc:-:*:*:*:*:*:*:*

  • Configuration 17:
  • cpe:/o:siemens:simatic_reader_rf650r_arib_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)
  • AND
  • cpe:/h:siemens:simatic_reader_rf650r_arib:-:*:*:*:*:*:*:*

  • Configuration 18:
  • cpe:/o:siemens:simatic_reader_rf680r_cmiit_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)
  • AND
  • cpe:/h:siemens:simatic_reader_rf680r_cmiit:-:*:*:*:*:*:*:*

  • Configuration 19:
  • cpe:/o:siemens:simatic_reader_rf680r_etsi_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)
  • AND
  • cpe:/h:siemens:simatic_reader_rf680r_etsi:-:*:*:*:*:*:*:*

  • Configuration 20:
  • cpe:/o:siemens:simatic_reader_rf680r_fcc_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)
  • AND
  • cpe:/h:siemens:simatic_reader_rf680r_fcc:-:*:*:*:*:*:*:*

  • Configuration 21:
  • cpe:/o:siemens:simatic_reader_rf680r_arib_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)
  • AND
  • cpe:/h:siemens:simatic_reader_rf680r_arib:-:*:*:*:*:*:*:*

  • Configuration 22:
  • cpe:/o:siemens:simatic_reader_rf685r_cmiit_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)
  • AND
  • cpe:/h:siemens:simatic_reader_rf685r_cmiit:-:*:*:*:*:*:*:*

  • Configuration 23:
  • cpe:/o:siemens:simatic_reader_rf685r_etsi_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)
  • AND
  • cpe:/h:siemens:simatic_reader_rf685r_etsi:-:*:*:*:*:*:*:*

  • Configuration 24:
  • cpe:/o:siemens:simatic_reader_rf685r_fcc_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)
  • AND
  • cpe:/h:siemens:simatic_reader_rf685r_fcc:-:*:*:*:*:*:*:*

  • Configuration 25:
  • cpe:/o:siemens:simatic_reader_rf685r_arib_firmware:*:*:*:*:*:*:*:* (Version >= 3.0 and < 4.0)
  • AND
  • cpe:/h:siemens:simatic_reader_rf685r_arib:-:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:siemens:simatic_rf166c_firmware:1.3.2:*:*:*:*:*:*:*
  • OR cpe:/o:siemens:simatic_rf188ci_firmware:1.3.2:*:*:*:*:*:*:*
  • OR cpe:/o:siemens:simatic_rf680r_firmware:3.0:*:*:*:*:*:*:*
  • OR cpe:/o:siemens:simatic_rf685r_firmware:3.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    siemens simatic rf166c firmware *
    siemens simatic rf166c -
    siemens simatic rf185c firmware *
    siemens simatic rf185c -
    siemens simatic rf186c firmware *
    siemens simatic rf186c -
    siemens simatic rf186ci firmware *
    siemens simatic rf186ci -
    siemens simatic rf188c firmware *
    siemens simatic rf188c -
    siemens simatic rf188ci firmware *
    siemens simatic rf188ci -
    siemens simatic rf360r firmware *
    siemens simatic rf360r -
    siemens simatic reader rf610r cmiit firmware *
    siemens simatic reader rf610r cmiit -
    siemens simatic reader rf610r etsi firmware *
    siemens simatic reader rf610r etsi -
    siemens simatic reader rf610r fcc firmware *
    siemens simatic reader rf610r fcc -
    siemens simatic reader rf615r cmiit firmware *
    siemens simatic reader rf615r cmiit -
    siemens simatic reader rf615r etsi firmware *
    siemens simatic reader rf615r etsi -
    siemens simatic reader rf615r fcc firmware *
    siemens simatic reader rf615r fcc -
    siemens simatic reader rf650r cmiit firmware *
    siemens simatic reader rf650r cmiit -
    siemens simatic reader rf650r etsi firmware *
    siemens simatic reader rf650r etsi -
    siemens simatic reader rf650r fcc firmware *
    siemens simatic reader rf650r fcc -
    siemens simatic reader rf650r arib firmware *
    siemens simatic reader rf650r arib -
    siemens simatic reader rf680r cmiit firmware *
    siemens simatic reader rf680r cmiit -
    siemens simatic reader rf680r etsi firmware *
    siemens simatic reader rf680r etsi -
    siemens simatic reader rf680r fcc firmware *
    siemens simatic reader rf680r fcc -
    siemens simatic reader rf680r arib firmware *
    siemens simatic reader rf680r arib -
    siemens simatic reader rf685r cmiit firmware *
    siemens simatic reader rf685r cmiit -
    siemens simatic reader rf685r etsi firmware *
    siemens simatic reader rf685r etsi -
    siemens simatic reader rf685r fcc firmware *
    siemens simatic reader rf685r fcc -
    siemens simatic reader rf685r arib firmware *
    siemens simatic reader rf685r arib -
    siemens simatic rf166c firmware 1.3.2
    siemens simatic rf188ci firmware 1.3.2
    siemens simatic rf680r firmware 3.0
    siemens simatic rf685r firmware 3.0