CVE Feed

    Dashboard / CVE / CVE-2021-25667

    CVE-2021-25667

    A vulnerability has been identified in RUGGEDCOM RM1224 (All versions >= V4.3 and < V6.4), SCALANCE M-800 (All versions >= V4.3 and < V6.4), SCALANCE S615 (All versions >= V4.3 and < V6.4), SCALANCE SC-600 Family (All versions >= V2.0 and < V2.1.3), SCALANCE XB-200 (All versions < V4.1), SCALANCE XC-200 (All versions < V4.1), SCALANCE XF-200BA (All versions < V4.1), SCALANCE XM400 (All versions < V6.2), SCALANCE XP-200 (All versions < V4.1), SCALANCE XR-300WG (All versions < V4.1), SCALANCE XR500 (All versions < V6.2). Affected devices contain a stack-based buffer overflow vulnerability in the handling of STP BPDU frames that could allow a remote attacker to trigger a denial-of-service condition or potentially remote code execution. Successful exploitation requires the passive listening feature of the device to be active.

    Published:Mar 15, 2021
    Last Modified:Jun 2, 2026
    EPS:Mar 15, 2021
    EPSS Score:0.00305
    CVSS Score:6.5

    Affected Products

    Vendor
    Siemens
    Product
    Ruggedcom Rm1224
    Vendor
    Siemens
    Product
    Ruggedcom Rm1224 Firmware
    Vendor
    Siemens
    Product
    Scalance M-800
    Vendor
    Siemens
    Product
    Scalance M-800 Firmware
    Vendor
    Siemens
    Product
    Scalance S615
    Vendor
    Siemens
    Product
    Scalance S615 Firmware
    Vendor
    Siemens
    Product
    Scalance Sc622-2c
    Vendor
    Siemens
    Product
    Scalance Sc622-2c Firmware
    Vendor
    Siemens
    Product
    Scalance Sc632-2c
    Vendor
    Siemens
    Product
    Scalance Sc632-2c Firmware
    Vendor
    Siemens
    Product
    Scalance Sc636-2c
    Vendor
    Siemens
    Product
    Scalance Sc636-2c Firmware
    Vendor
    Siemens
    Product
    Scalance Sc642-2c
    Vendor
    Siemens
    Product
    Scalance Sc642-2c Firmware
    Vendor
    Siemens
    Product
    Scalance Sc646-2c
    Vendor
    Siemens
    Product
    Scalance Sc646-2c Firmware
    Vendor
    Siemens
    Product
    Scalance X300wg
    Vendor
    Siemens
    Product
    Scalance X300wg Firmware
    Vendor
    Siemens
    Product
    Scalance Xb-200
    Vendor
    Siemens
    Product
    Scalance Xb-200 Firmware
    Vendor
    Siemens
    Product
    Scalance Xc-200
    Vendor
    Siemens
    Product
    Scalance Xc-200 Firmware
    Vendor
    Siemens
    Product
    Scalance Xf-200ba
    Vendor
    Siemens
    Product
    Scalance Xf-200ba Firmware
    Vendor
    Siemens
    Product
    Scalance Xm400
    Vendor
    Siemens
    Product
    Scalance Xm400 Firmware
    Vendor
    Siemens
    Product
    Scalance Xp-200
    Vendor
    Siemens
    Product
    Scalance Xp-200 Firmware
    Vendor
    Siemens
    Product
    Scalance Xr500
    Vendor
    Siemens
    Product
    Scalance Xr500 Firmware

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High