| Publication Date: |
2021-09-14 |
| Last Update: |
2021-09-14 |
| Current Version: |
V1.0 |
| CVSS v3.1 Base Score: |
9.8 |
- Please contact your local Siemens office for support
- Restrict access to the device, especially to the web interface (80/tcp and 443/tcp), to trusted IP addresses only
- Disable the integrated web server
| CVSS v3.1 Base Score |
9.8 |
| CVSS Vector |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:T/RC:C |
| CWE: |
CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) |
-
Paul Noalhyt and David Doggett from
Red Balloon Security
for coordinated disclosure
https://www.siemens.com/cert/advisories