CVE-2021-41545

A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). When the controller receives a specific BACnet protocol packet, an exception causes the BACnet communication function to go into a “out of work” state and could result in the controller going into a “factory reset” state.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:siemens:desigo_dxr2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:desigo_dxr2:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:siemens:desigo_pxc3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:desigo_pxc3:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:siemens:desigo_pxc4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:desigo_pxc4:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:siemens:desigo_pxc5_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:desigo_pxc5:-:*:*:*:*:*:*:*

History

19 May 2022, 17:09

Type Values Removed Values Added
CWE NVD-CWE-noinfo
First Time Siemens desigo Pxc3 Firmware
Siemens desigo Pxc4
Siemens desigo Pxc3
Siemens desigo Pxc4 Firmware
Siemens
Siemens desigo Pxc5 Firmware
Siemens desigo Dxr2 Firmware
Siemens desigo Dxr2
Siemens desigo Pxc5
References (MISC) https://cert-portal.siemens.com/productcert/pdf/ssa-662649.pdf - (MISC) https://cert-portal.siemens.com/productcert/pdf/ssa-662649.pdf - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5
CPE cpe:2.3:h:siemens:desigo_dxr2:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:desigo_dxr2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:desigo_pxc4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:desigo_pxc3:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:desigo_pxc5_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:desigo_pxc5:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:desigo_pxc4:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:desigo_pxc3_firmware:*:*:*:*:*:*:*:*

10 May 2022, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-05-10 11:15

Updated : 2023-12-10 14:22


NVD link : CVE-2021-41545

Mitre link : CVE-2021-41545

CVE.ORG link : CVE-2021-41545


JSON object : View

Products Affected

siemens

  • desigo_pxc3_firmware
  • desigo_pxc4_firmware
  • desigo_dxr2_firmware
  • desigo_pxc5
  • desigo_dxr2
  • desigo_pxc4
  • desigo_pxc5_firmware
  • desigo_pxc3
CWE
NVD-CWE-noinfo CWE-248

Uncaught Exception