Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2021-31890
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions), SIMOTICS CONNECT 400 (All versions < V0.5.0.0), SIMOTICS CONNECT 400 (All versions < V1.0.0.0). The total length of an TCP payload (set in the IP header) is unchecked. This may lead to various side effects, including Information Leak and Denial-of-Service conditions, depending on the network buffer organization in memory. (FSMD-2021-0017)
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
对不一致结构体元素处理不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
Siemens Nucleus ReadyStart 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Siemens Nucleus ReadyStart是德国Siemens公司的一个捆绑式解决方案。用于加速完整系统的快速启动并提供丰富的板级支持包 (Bsp) Siemens Nucleus ReadyStart 存在安全漏洞,该漏洞源于 TCP 有效负载的总长度(在 IP 标头中设置)未选中。这可能会导致各种副作用,包括信息泄漏和拒绝服务条件,具体取决于内存中的网络缓冲区组织。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
SiemensCapital Embedded AR Classic 431-422 0 ~ * -
SiemensCapital Embedded AR Classic R20-11 0 ~ V2303 -
SiemensPLUSCONTROL 1st Gen All versions -
SiemensSIMOTICS CONNECT 400 All versions < V0.5.0.0 -
SiemensSIMOTICS CONNECT 400 All versions < V1.0.0.0 -
II. Public POCs for CVE-2021-31890
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2021-31890
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2021-31890

No comments yet


Leave a comment