CVE Feed

    Dashboard / CVE / CVE-2021-37182

    CVE-2021-37182

    A vulnerability has been identified in SCALANCE XM408-4C (All versions < V6.5), SCALANCE XM408-4C (L3 int.) (All versions < V6.5), SCALANCE XM408-8C (All versions < V6.5), SCALANCE XM408-8C (L3 int.) (All versions < V6.5), SCALANCE XM416-4C (All versions < V6.5), SCALANCE XM416-4C (L3 int.) (All versions < V6.5), SCALANCE XR524-8C, 1x230V (All versions < V6.5), SCALANCE XR524-8C, 1x230V (L3 int.) (All versions < V6.5), SCALANCE XR524-8C, 24V (All versions < V6.5), SCALANCE XR524-8C, 24V (L3 int.) (All versions < V6.5), SCALANCE XR524-8C, 2x230V (All versions < V6.5), SCALANCE XR524-8C, 2x230V (L3 int.) (All versions < V6.5), SCALANCE XR526-8C, 1x230V (All versions < V6.5), SCALANCE XR526-8C, 1x230V (L3 int.) (All versions < V6.5), SCALANCE XR526-8C, 24V (All versions < V6.5), SCALANCE XR526-8C, 24V (L3 int.) (All versions < V6.5), SCALANCE XR526-8C, 2x230V (All versions < V6.5), SCALANCE XR526-8C, 2x230V (L3 int.) (All versions < V6.5), SCALANCE XR528-6M (All versions < V6.5), SCALANCE XR528-6M (2HR2) (All versions < V6.5), SCALANCE XR528-6M (2HR2, L3 int.) (All versions < V6.5), SCALANCE XR528-6M (L3 int.) (All versions < V6.5), SCALANCE XR552-12M (All versions < V6.5), SCALANCE XR552-12M (2HR2) (All versions < V6.5), SCALANCE XR552-12M (2HR2) (All versions < V6.5), SCALANCE XR552-12M (2HR2, L3 int.) (All versions < V6.5). The OSPF protocol implementation in affected devices fails to verify the checksum and length fields in the OSPF LS Update messages. An unauthenticated remote attacker could exploit this vulnerability to cause interruptions in the network by sending specially crafted OSPF packets. Successful exploitation requires OSPF to be enabled on an affected device.

    Published:Jun 14, 2022
    Last Modified:Nov 21, 2024
    EPS:Jun 14, 2022
    EPSS Score:0.00346
    CVSS Score:7.5

    Affected Products

    Vendor
    Siemens
    Product
    Scalance Xm408-4c
    Vendor
    Siemens
    Product
    Scalance Xm408-4c Firmware
    Vendor
    Siemens
    Product
    Scalance Xm408-4c L3
    Vendor
    Siemens
    Product
    Scalance Xm408-4c L3 Firmware
    Vendor
    Siemens
    Product
    Scalance Xm408-8c
    Vendor
    Siemens
    Product
    Scalance Xm408-8c Firmware
    Vendor
    Siemens
    Product
    Scalance Xm408-8c L3
    Vendor
    Siemens
    Product
    Scalance Xm408-8c L3 Firmware
    Vendor
    Siemens
    Product
    Scalance Xm416-4c
    Vendor
    Siemens
    Product
    Scalance Xm416-4c Firmware
    Vendor
    Siemens
    Product
    Scalance Xm416-4c L3
    Vendor
    Siemens
    Product
    Scalance Xm416-4c L3 Firmware
    Vendor
    Siemens
    Product
    Scalance Xr524-8c
    Vendor
    Siemens
    Product
    Scalance Xr524-8c Firmware
    Vendor
    Siemens
    Product
    Scalance Xr524-8c L3
    Vendor
    Siemens
    Product
    Scalance Xr524-8c L3 Firmware
    Vendor
    Siemens
    Product
    Scalance Xr526-8c
    Vendor
    Siemens
    Product
    Scalance Xr526-8c Firmware
    Vendor
    Siemens
    Product
    Scalance Xr526-8c L3
    Vendor
    Siemens
    Product
    Scalance Xr526-8c L3 Firmware
    Vendor
    Siemens
    Product
    Scalance Xr528-6m
    Vendor
    Siemens
    Product
    Scalance Xr528-6m 2hr2
    Vendor
    Siemens
    Product
    Scalance Xr528-6m 2hr2 Firmware
    Vendor
    Siemens
    Product
    Scalance Xr528-6m 2hr2 L3
    Vendor
    Siemens
    Product
    Scalance Xr528-6m 2hr2 L3 Firmware
    Vendor
    Siemens
    Product
    Scalance Xr528-6m Firmware
    Vendor
    Siemens
    Product
    Scalance Xr528-6m L3
    Vendor
    Siemens
    Product
    Scalance Xr528-6m L3 Firmware
    Vendor
    Siemens
    Product
    Scalance Xr552-12m
    Vendor
    Siemens
    Product
    Scalance Xr552-12m 2hr2
    Vendor
    Siemens
    Product
    Scalance Xr552-12m 2hr2 Firmware
    Vendor
    Siemens
    Product
    Scalance Xr552-12m 2hr2 L3
    Vendor
    Siemens
    Product
    Scalance Xr552-12m 2hr2 L3 Firmware
    Vendor
    Siemens
    Product
    Scalance Xr552-12m Firmware

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High