CVE-2021-31882 MEDIUM

CVE-2021-31882

Vendor Siemens
Product Capital Embedded AR Classic 431-422
Weakness CWE-119
Published November 9, 2021
Last update March 11, 2025

CVSS base score

6.5/10
Attack vector Adjacent
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

What the vulnerability does

01Description

A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303). The DHCP client application does not validate the length of the Domain Name Server IP option(s) (0x06) when processing DHCP ACK packets. This may lead to Denial-of-Service conditions. (FSMD-2021-0011)

Key dates

02Disclosure timeline

November 9, 2021 CVE published
March 11, 2025 Record updated