First published: Tue Jun 08 2021(Updated: )
A vulnerability has been identified in SIMATIC RF166C (All versions > V1.1 and < V1.3.2), SIMATIC RF185C (All versions > V1.1 and < V1.3.2), SIMATIC RF186C (All versions > V1.1 and < V1.3.2), SIMATIC RF186CI (All versions > V1.1 and < V1.3.2), SIMATIC RF188C (All versions > V1.1 and < V1.3.2), SIMATIC RF188CI (All versions > V1.1 and < V1.3.2), SIMATIC RF360R (All versions < V2.0), SIMATIC Reader RF610R CMIIT (All versions > V3.0 < V4.0), SIMATIC Reader RF610R ETSI (All versions > V3.0 < V4.0), SIMATIC Reader RF610R FCC (All versions > V3.0 < V4.0), SIMATIC Reader RF615R CMIIT (All versions > V3.0 < V4.0), SIMATIC Reader RF615R ETSI (All versions > V3.0 < V4.0), SIMATIC Reader RF615R FCC (All versions > V3.0 < V4.0), SIMATIC Reader RF650R ARIB (All versions > V3.0 < V4.0), SIMATIC Reader RF650R CMIIT (All versions > V3.0 < V4.0), SIMATIC Reader RF650R ETSI (All versions > V3.0 < V4.0), SIMATIC Reader RF650R FCC (All versions > V3.0 < V4.0), SIMATIC Reader RF680R ARIB (All versions > V3.0 < V4.0), SIMATIC Reader RF680R CMIIT (All versions > V3.0 < V4.0), SIMATIC Reader RF680R ETSI (All versions > V3.0 < V4.0), SIMATIC Reader RF680R FCC (All versions > V3.0 < V4.0), SIMATIC Reader RF685R ARIB (All versions > V3.0 < V4.0), SIMATIC Reader RF685R CMIIT (All versions > V3.0 < V4.0), SIMATIC Reader RF685R ETSI (All versions > V3.0 < V4.0), SIMATIC Reader RF685R FCC (All versions > V3.0 < V4.0). Affected devices do not properly handle large numbers of incoming connections. An attacker may leverage this to cause a Denial-of-Service situation.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
siemens simatic rf166c firmware | >1.1<1.3.2 | |
siemens simatic rf166c | ||
Siemens Simatic RF185C Firmware | >1.1<1.3.2 | |
Siemens Simatic RF185C Firmware | ||
Siemens Simatic RF186C | >1.1<1.3.2 | |
Siemens Simatic RF186C | ||
Siemens Simatic RF186CI | >1.1<1.3.2 | |
Siemens Simatic RF186CI | ||
Siemens SIMATIC RF188C Firmware | >1.1<1.3.2 | |
Siemens Simatic RF188C | ||
Siemens Simatic RF188CI Firmware | >1.1<1.3.2 | |
Siemens Simatic RF188CI Firmware | ||
siemens simatic rf360r firmware | <2.0 | |
siemens simatic rf360r | ||
Siemens SIMATIC Reader RF610R CMIIT | >=3.0<4.0 | |
Siemens SIMATIC Reader RF610R | ||
Siemens SIMATIC Reader RF610R ETSI | >=3.0<4.0 | |
Siemens SIMATIC Reader RF610R | ||
Siemens SIMATIC Reader RF610R FCC | >=3.0<4.0 | |
Siemens SIMATIC Reader RF610R | ||
Siemens SIMATIC Reader RF615R CMIIT | >=3.0<4.0 | |
Siemens SIMATIC Reader RF615R CMIIT | ||
Siemens SIMATIC Reader RF615R ETSI | >=3.0<4.0 | |
Siemens SIMATIC Reader RF615R ETSI firmware | ||
Siemens SIMATIC Reader RF615R FCC | >=3.0<4.0 | |
Siemens SIMATIC Reader RF615R CMIIT | ||
Siemens SIMATIC Reader RF650R CMIIT | >=3.0<4.0 | |
Siemens SIMATIC Reader RF650R FCC | ||
siemens SIMATIC Reader RF650R ETSI firmware | >=3.0<4.0 | |
siemens SIMATIC Reader RF650R ETSI | ||
Siemens SIMATIC Reader RF650R FCC | >=3.0<4.0 | |
Siemens SIMATIC Reader RF650R FCC firmware | ||
Siemens SIMATIC Reader RF650R ARIB firmware | >=3.0<4.0 | |
Siemens SIMATIC Reader RF650R ARIB firmware | ||
siemens SIMATIC Reader RF680R CMIIT | >=3.0<4.0 | |
siemens SIMATIC Reader RF680R CMIIT | ||
Siemens SIMATIC Reader RF680R ETSI | >=3.0<4.0 | |
Siemens SIMATIC Reader RF680R ETSI | ||
Siemens SIMATIC Reader RF680R FCC | >=3.0<4.0 | |
Siemens SIMATIC Reader RF680R FCC | ||
Siemens SIMATIC RF680R ARIB | >=3.0<4.0 | |
Siemens SIMATIC RF680R ARIB | ||
Siemens SIMATIC Reader RF685R CMIIT Firmware | >=3.0<4.0 | |
Siemens SIMATIC Reader RF685R CMIIT | ||
siemens SIMATIC Reader RF685R ETSI | >=3.0<4.0 | |
Siemens SIMATIC Reader RF685R ETSI Firmware | ||
Siemens SIMATIC Reader RF685R FCC | >=3.0<4.0 | |
Siemens SIMATIC Reader RF685R FCC | ||
siemens SIMATIC Reader RF685R ARIB | >=3.0<4.0 | |
siemens SIMATIC Reader RF685R ARIB firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-31340.
The SIMATIC RF166C, SIMATIC RF185C, SIMATIC RF186C, SIMATIC RF186CI, and SIMATIC RF188C are affected.
The severity of CVE-2021-31340 is high with a CVSS score of 7.5.
To fix CVE-2021-31340, update to versions higher than V1.1 and lower than V1.3.2 for the affected products.
You can find more information about CVE-2021-31340 at https://cert-portal.siemens.com/productcert/pdf/ssa-787292.pdf.