CVE-2021-25664 Details
Description
A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), Nucleus NET (All versions), Nucleus ReadyStart V3 (All versions < V2017.02.4), Nucleus ReadyStart V4 (All versions < V4.1.0), Nucleus Source Code (All versions including affected IPv6 stack). The function that processes the Hop-by-Hop extension header in IPv6 packets and its options lacks any checks against the length field of the header, allowing attackers to put the function into an infinite loop by supplying arbitrary length values.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-248289.html | CVE | |
| https://cert-portal.siemens.com/productcert/pdf/ssa-248289.pdf | CVE | Vendor Advisory |
| https://us-cert.cisa.gov/ics/advisories/icsa-21-103-05 | CVE | Third Party AdvisoryUS Government Resource |
| https://cert-portal.siemens.com/productcert/html/ssa-248289.html | [email protected] | |
| https://cert-portal.siemens.com/productcert/pdf/ssa-248289.pdf | [email protected] | Vendor Advisory |
| https://us-cert.cisa.gov/ics/advisories/icsa-21-103-05 | [email protected] | Third Party AdvisoryUS Government Resource |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-835 | Loop with Unreachable Exit Condition ('Infinite Loop') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| siemens capital vstar | All versions |
CPE
Remediation
| |
| siemens nucleus net | All versions |
CPE
Remediation
| |
| siemens nucleus readystart v3 | < 2017.02.4 |
CPE
Remediation
| |
| siemens nucleus readystart v4 | < 4.1.0 |
CPE
Remediation
| |
| siemens nucleus source code | All versions |
CPE
Remediation
| |
Change History
12 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Mar 11, 2025 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Feb 13, 2024 | CVE Modified | [email protected] |
| May 1, 2022 | Modified Analysis | [email protected] |
| Nov 17, 2021 | CVE Modified | [email protected] |
| Nov 11, 2021 | Modified Analysis | [email protected] |
| Nov 10, 2021 | CVE Modified | [email protected] |
| Nov 9, 2021 | CVE Modified | [email protected] |
| Apr 30, 2021 | Initial Analysis | [email protected] |
| Apr 23, 2021 | CVE Modified | [email protected] |