Publication Date: 2021-04-13
Last Update: 2022-01-11
Current Version: V1.2
CVSS v3.1 Base Score: 5.3

Affected Product and Versions Remediation
Nucleus NET:
All versions
Currently no remediation is planned
Update to the latest version of Nucleus ReadyStart V3 or V4
Contact customer support or your local Nucleus Sales team for mitigation advice
See further recommendations from section Workarounds and Mitigations
Nucleus ReadyStart V3:
All versions < V2013.08
Update to V2013.08 or later version
https://support.sw.siemens.com/en-US/product/1009925838/
See further recommendations from section Workarounds and Mitigations
Nucleus Source Code:
Versions including affected DNS modules
Contact customer support to receive patch and update information
See further recommendations from section Workarounds and Mitigations

CVSS v3.1 Base Score 5.3
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C
CWE: CWE-330: Use of Insufficiently Random Values

https://www.siemens.com/cert/advisories