Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-89445
HistoryNov 11, 2021 - 12:00 a.m.

Incorrect Input Validation Vulnerability in Multiple Siemens Products

2021-11-1100:00:00
China National Vulnerability Database
www.cnvd.org.cn
18
siemens
input validation
security vulnerability
udp protocol
information disclosure
denial of service
nucleus rtos

EPSS

0.004

Percentile

73.4%

Capital VSTAR is a complete solution. the Nucleus NET module integrates a range of standards-compliant networking and communications protocols, drivers and utilities to provide full-featured networking support in any embedded device. the Nucleus RTOS is a microkernel-based real-time operating system. A security vulnerability exists in several Siemens products. The vulnerability stems from the total length of the UDP payload (set in the IP header) being unchecked. An attacker can exploit the vulnerability to cause information disclosure and denial of service conditions, depending on the user-defined application running on top of the UDP protocol.

EPSS

0.004

Percentile

73.4%

Related for CNVD-2021-89445