Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2021-25664 Details

Description

A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), Nucleus NET (All versions), Nucleus ReadyStart V3 (All versions < V2017.02.4), Nucleus ReadyStart V4 (All versions < V4.1.0), Nucleus Source Code (All versions including affected IPv6 stack). The function that processes the Hop-by-Hop extension header in IPv6 packets and its options lacks any checks against the length field of the header, allowing attackers to put the function into an infinite loop by supplying arbitrary length values.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-835Loop with Unreachable Exit Condition ('Infinite Loop')[email protected]

Affected Products

ProductVersions
siemens capital vstar
All versions

CPE

  • cpe:2.3:a:siemens:capital_vstar:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
siemens nucleus net
All versions

CPE

  • cpe:2.3:a:siemens:nucleus_net:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
siemens nucleus readystart v3
< 2017.02.4

CPE

  • cpe:2.3:a:siemens:nucleus_readystart_v3:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
siemens nucleus readystart v4
< 4.1.0

CPE

  • cpe:2.3:a:siemens:nucleus_readystart_v4:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
siemens nucleus source code
All versions

CPE

  • cpe:2.3:a:siemens:nucleus_source_code:-:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

12 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2021-25664
NVD Published Date:
Apr 22, 2021
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2021-25664 Details - Not Deferred