Publication Date: 2021-11-09
Last Update: 2021-12-14
Current Version: V1.1
CVSS v3.1 Base Score: 9.8

Affected Product and Versions Remediation
Nucleus NET:
All versions
Currently no remediation is planned
Update to the latest version of Nucleus ReadyStart V3 or V4
Contact customer support or your local Nucleus Sales team for mitigation advice
Nucleus ReadyStart V3:
All versions < V2017.02.4
Update to V2017.02.4 or later version
https://support.sw.siemens.com/en-US/product/1009925838/
Nucleus ReadyStart V4:
All versions < V4.1.1
only affected by CVE-2021-31344, CVE-2021-31346, CVE-2021-31885, CVE-2021-31890
Update to V4.1.1 or later version
https://support.sw.siemens.com/en-US/product/1336134128/
Nucleus Source Code:
All versions
Contact customer support to receive patch and update information

CVSS v3.1 Base Score 5.3
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C
CWE: CWE-843: Access of Resource Using Incompatible Type (‘Type Confusion’)

CVSS v3.1 Base Score 7.5
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C
CWE: CWE-1284: Improper Validation of Specified Quantity in Input

CVSS v3.1 Base Score 8.2
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H/E:P/RL:O/RC:C
CWE: CWE-1284: Improper Validation of Specified Quantity in Input

CVSS v3.1 Base Score 7.1
CVSS Vector CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H/E:P/RL:O/RC:C
CWE: CWE-125: Out-of-bounds Read

CVSS v3.1 Base Score 6.5
CVSS Vector CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C
CWE: CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer

CVSS v3.1 Base Score 7.1
CVSS Vector CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H/E:P/RL:O/RC:C
CWE: CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer

CVSS v3.1 Base Score 8.8
CVSS Vector CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-170: Improper Null Termination

CVSS v3.1 Base Score 7.5
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C
CWE: CWE-805: Buffer Access with Incorrect Length Value

CVSS v3.1 Base Score 9.8
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-170: Improper Null Termination

CVSS v3.1 Base Score 8.8
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-170: Improper Null Termination

CVSS v3.1 Base Score 8.8
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-170: Improper Null Termination

CVSS v3.1 Base Score 7.5
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C
CWE: CWE-191: Integer Underflow (Wrap or Wraparound)

CVSS v3.1 Base Score 7.5
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C
CWE: CWE-240: Improper Handling of Inconsistent Structural Elements

https://www.siemens.com/cert/advisories