CVE-2021-27391: Buffer Overflow
A vulnerability has been identified in APOGEE MBC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE MEC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE PXC Compact (BACnet) (All versions < V3.5.3), APOGEE PXC Compact (P2 Ethernet) (All versions >= V2.8), APOGEE PXC Modular (BACnet) (All versions < V3.5.3), APOGEE PXC Modular (P2 Ethernet) (All versions >= V2.8), TALON TC Compact (BACnet) (All versions < V3.5.3), TALON TC Modular (BACnet) (All versions < V3.5.3). The web server of affected devices lacks proper bounds checking when parsing the Host parameter in HTTP requests, which could lead to a buffer overflow. An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary code on the device with root privileges.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27391?
CVE-2021-27391 has been classified with a medium severity rating.
How do I fix CVE-2021-27391?
To mitigate the effects of CVE-2021-27391, upgrade affected Siemens APOGEE products to the latest available firmware versions.
Which versions are affected by CVE-2021-27391?
CVE-2021-27391 affects Siemens APOGEE MBC, MEC, PXC Compact, and PXC Modular products running specific firmware versions prior to the recommended updates.
What are the implications of CVE-2021-27391?
Exploitation of CVE-2021-27391 could allow an attacker to compromise the affected systems and disrupt operations.
Is there a patch available for CVE-2021-27391?
Yes, Siemens has provided patches for CVE-2021-27391 and users are encouraged to apply them promptly.