CVE-2021-25676

A vulnerability has been identified in RUGGEDCOM RM1224 (V6.3), SCALANCE M-800 (V6.3), SCALANCE S615 (V6.3), SCALANCE SC-600 (All Versions >= V2.1 and < V2.1.3). Multiple failed SSH authentication attempts could trigger a temporary Denial-of-Service under certain conditions. When triggered, the device will reboot automatically.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:siemens:ruggedcom_rm1224_firmware:6.3:*:*:*:*:*:*:*
cpe:2.3:h:siemens:ruggedcom_rm1224:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:siemens:scalance_m-800_firmware:6.3:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_m-800:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:siemens:scalance_s615_firmware:6.3:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_s615:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:siemens:scalance_sc-600_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_sc-600:-:*:*:*:*:*:*:*

History

20 Apr 2021, 17:41

Type Values Removed Values Added
References (CONFIRM) https://us-cert.cisa.gov/ics/advisories/icsa-21-068-02 - (CONFIRM) https://us-cert.cisa.gov/ics/advisories/icsa-21-068-02 - Third Party Advisory, US Government Resource

15 Apr 2021, 21:15

Type Values Removed Values Added
References
  • (CONFIRM) https://us-cert.cisa.gov/ics/advisories/icsa-21-068-02 -

18 Mar 2021, 17:10

Type Values Removed Values Added
CPE cpe:2.3:o:siemens:scalance_sc-600_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_m-800:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_s615:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:scalance_s615_firmware:6.3:*:*:*:*:*:*:*
cpe:2.3:o:siemens:ruggedcom_rm1224_firmware:6.3:*:*:*:*:*:*:*
cpe:2.3:o:siemens:scalance_m-800_firmware:6.3:*:*:*:*:*:*:*
cpe:2.3:h:siemens:scalance_sc-600:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:ruggedcom_rm1224:-:*:*:*:*:*:*:*
References (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-296266.pdf - (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-296266.pdf - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5

15 Mar 2021, 18:15

Type Values Removed Values Added
Summary A vulnerability has been identified in RUGGEDCOM RM1224 (V6.3), SCALANCE M-800 (V6.3), SCALANCE S615 (V6.3), SCALANCE SC-600 (All Versions >= V2.1 and < V2.1.3). Multiple failed SSH authentication attempts could trigger a temporary Denial-of-Service under certain conditions. When triggered, the device will reboot automatically. A vulnerability has been identified in RUGGEDCOM RM1224 (V6.3), SCALANCE M-800 (V6.3), SCALANCE S615 (V6.3), SCALANCE SC-600 (All Versions >= V2.1 and < V2.1.3). Multiple failed SSH authentication attempts could trigger a temporary Denial-of-Service under certain conditions. When triggered, the device will reboot automatically.

15 Mar 2021, 18:00

Type Values Removed Values Added
New CVE

Information

Published : 2021-03-15 17:15

Updated : 2023-12-10 13:41


NVD link : CVE-2021-25676

Mitre link : CVE-2021-25676

CVE.ORG link : CVE-2021-25676


JSON object : View

Products Affected

siemens

  • ruggedcom_rm1224
  • scalance_sc-600_firmware
  • scalance_m-800
  • scalance_s615_firmware
  • scalance_m-800_firmware
  • scalance_s615
  • ruggedcom_rm1224_firmware
  • scalance_sc-600
CWE
CWE-307

Improper Restriction of Excessive Authentication Attempts