CVE-2021-37182

Description

A vulnerability has been identified in SCALANCE XM408-4C (All versions < V6.5), SCALANCE XM408-4C (L3 int.) (All versions < V6.5), SCALANCE XM408-8C (All versions < V6.5), SCALANCE XM408-8C (L3 int.) (All versions < V6.5), SCALANCE XM416-4C (All versions < V6.5), SCALANCE XM416-4C (L3 int.) (All versions < V6.5), SCALANCE XR524-8C, 1x230V (All versions < V6.5), SCALANCE XR524-8C, 1x230V (L3 int.) (All versions < V6.5), SCALANCE XR524-8C, 24V (All versions < V6.5), SCALANCE XR524-8C, 24V (L3 int.) (All versions < V6.5), SCALANCE XR524-8C, 2x230V (All versions < V6.5), SCALANCE XR524-8C, 2x230V (L3 int.) (All versions < V6.5), SCALANCE XR526-8C, 1x230V (All versions < V6.5), SCALANCE XR526-8C, 1x230V (L3 int.) (All versions < V6.5), SCALANCE XR526-8C, 24V (All versions < V6.5), SCALANCE XR526-8C, 24V (L3 int.) (All versions < V6.5), SCALANCE XR526-8C, 2x230V (All versions < V6.5), SCALANCE XR526-8C, 2x230V (L3 int.) (All versions < V6.5), SCALANCE XR528-6M (All versions < V6.5), SCALANCE XR528-6M (2HR2) (All versions < V6.5), SCALANCE XR528-6M (2HR2, L3 int.) (All versions < V6.5), SCALANCE XR528-6M (L3 int.) (All versions < V6.5), SCALANCE XR552-12M (All versions < V6.5), SCALANCE XR552-12M (2HR2) (All versions < V6.5), SCALANCE XR552-12M (2HR2) (All versions < V6.5), SCALANCE XR552-12M (2HR2, L3 int.) (All versions < V6.5). The OSPF protocol implementation in affected devices fails to verify the checksum and length fields in the OSPF LS Update messages. An unauthenticated remote attacker could exploit this vulnerability to cause interruptions in the network by sending specially crafted OSPF packets. Successful exploitation requires OSPF to be enabled on an affected device.

Category

7.5
CVSS
Severity: High
CVSS 3.1 •
CVSS 2.0 •
EPSS 0.53%
Vendor Advisory siemens.com
Affected: Siemens SCALANCE XM408-4C
Affected: Siemens SCALANCE XM408-4C (L3 int.)
Affected: Siemens SCALANCE XM408-8C
Affected: Siemens SCALANCE XM408-8C (L3 int.)
Affected: Siemens SCALANCE XM416-4C
Affected: Siemens SCALANCE XM416-4C (L3 int.)
Affected: Siemens SCALANCE XR524-8C, 1x230V
Affected: Siemens SCALANCE XR524-8C, 1x230V (L3 int.)
Affected: Siemens SCALANCE XR524-8C, 24V
Affected: Siemens SCALANCE XR524-8C, 24V (L3 int.)
Affected: Siemens SCALANCE XR524-8C, 2x230V
Affected: Siemens SCALANCE XR524-8C, 2x230V (L3 int.)
Affected: Siemens SCALANCE XR526-8C, 1x230V
Affected: Siemens SCALANCE XR526-8C, 1x230V (L3 int.)
Affected: Siemens SCALANCE XR526-8C, 24V
Affected: Siemens SCALANCE XR526-8C, 24V (L3 int.)
Affected: Siemens SCALANCE XR526-8C, 2x230V
Affected: Siemens SCALANCE XR526-8C, 2x230V (L3 int.)
Affected: Siemens SCALANCE XR528-6M
Affected: Siemens SCALANCE XR528-6M (2HR2)
Affected: Siemens SCALANCE XR528-6M (2HR2, L3 int.)
Affected: Siemens SCALANCE XR528-6M (L3 int.)
Affected: Siemens SCALANCE XR552-12M
Affected: Siemens SCALANCE XR552-12M (2HR2)
Affected: Siemens SCALANCE XR552-12M (2HR2)
Affected: Siemens SCALANCE XR552-12M (2HR2, L3 int.)
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2021-37182?
CVE-2021-37182 has been scored as a high severity vulnerability.
How to fix CVE-2021-37182?
To fix CVE-2021-37182, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2021-37182 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2021-37182 is being actively exploited. According to its EPSS score, there is a ~1% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2021-37182?
CVE-2021-37182 affects Siemens SCALANCE XM408-4C, Siemens SCALANCE XM408-4C (L3 int.), Siemens SCALANCE XM408-8C, Siemens SCALANCE XM408-8C (L3 int.), Siemens SCALANCE XM416-4C, Siemens SCALANCE XM416-4C (L3 int.), Siemens SCALANCE XR524-8C, 1x230V, Siemens SCALANCE XR524-8C, 1x230V (L3 int.), Siemens SCALANCE XR524-8C, 24V, Siemens SCALANCE XR524-8C, 24V (L3 int.), Siemens SCALANCE XR524-8C, 2x230V, Siemens SCALANCE XR524-8C, 2x230V (L3 int.), Siemens SCALANCE XR526-8C, 1x230V, Siemens SCALANCE XR526-8C, 1x230V (L3 int.), Siemens SCALANCE XR526-8C, 24V, Siemens SCALANCE XR526-8C, 24V (L3 int.), Siemens SCALANCE XR526-8C, 2x230V, Siemens SCALANCE XR526-8C, 2x230V (L3 int.), Siemens SCALANCE XR528-6M, Siemens SCALANCE XR528-6M (2HR2), Siemens SCALANCE XR528-6M (2HR2, L3 int.), Siemens SCALANCE XR528-6M (L3 int.), Siemens SCALANCE XR552-12M, Siemens SCALANCE XR552-12M (2HR2), Siemens SCALANCE XR552-12M (2HR2), Siemens SCALANCE XR552-12M (2HR2, L3 int.).
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.