Publication Date: 2021-04-13
Last Update: 2022-01-11
Current Version: V1.2
CVSS v3.1 Base Score: 8.1

Affected Product and Versions Remediation
Nucleus NET:
All versions < V5.2
Currently no remediation is planned
Update to the latest version of Nucleus ReadyStart V3 or V4
Note that the latest version of Nucleus NET (V5.2) is not affected, but is already beyond end of software support
Contact customer support or your local Nucleus Sales team for mitigation advice
See further recommendations from section Workarounds and Mitigations
Nucleus Source Code:
Versions including affected DNS modules
Contact customer support to receive patch and update information
See further recommendations from section Workarounds and Mitigations

CVSS v3.1 Base Score 8.1
CVSS Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-787: Out-of-bounds Write

CVSS v3.1 Base Score 8.1
CVSS Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-823: Use of Out-of-range Pointer Offset

https://www.siemens.com/cert/advisories