Vulnerability Description
An issue was discovered in Wind River VxWorks before 6.5. There is a possible heap overflow in dhcp client.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Windriver | Vxworks | < 6.5 |
| Siemens | Ruggedcom Win Subscriber Station Firmware | All versions |
| Siemens | Ruggedcom Win Subscriber Station | - |
| Siemens | Scalance X200-4 P Irt Firmware | All versions |
| Siemens | Scalance X200-4 P Irt | - |
| Siemens | Scalance X201-3P Irt Firmware | All versions |
| Siemens | Scalance X201-3P Irt | - |
| Siemens | Scalance X201-3P Irt Pro Firmware | All versions |
| Siemens | Scalance X201-3P Irt Pro | - |
| Siemens | Scalance X202-2 Irt Firmware | All versions |
| Siemens | Scalance X202-2 Irt | - |
| Siemens | Scalance X202-2P Irt Firmware | All versions |
| Siemens | Scalance X202-2P Irt | - |
| Siemens | Scalance X202-2P Irt Pro Firmware | All versions |
| Siemens | Scalance X202-2P Irt Pro | - |
| Siemens | Scalance X204 Irt Firmware | All versions |
| Siemens | Scalance X204 Irt | - |
| Siemens | Scalance X204 Irt Pro Firmware | All versions |
| Siemens | Scalance X204 Irt Pro | - |
| Siemens | Scalance X204-2 Firmware | All versions |
Related Weaknesses (CWE)
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-560465.pdfThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-910883.pdfThird Party Advisory
- https://support2.windriver.com/index.php?page=security-noticesVendor Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-21-194-12Third Party AdvisoryUS Government Resource
- https://cert-portal.siemens.com/productcert/pdf/ssa-560465.pdfThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-910883.pdfThird Party Advisory
- https://support2.windriver.com/index.php?page=security-noticesVendor Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-21-194-12Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2021-29998?
CVE-2021-29998 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered in Wind River VxWorks before 6.5. There is a possible heap overflow in dhcp client.
How severe is CVE-2021-29998?
CVE-2021-29998 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-29998?
Check the references section above for vendor advisories and patch information. Affected products include: Windriver Vxworks, Siemens Ruggedcom Win Subscriber Station Firmware, Siemens Ruggedcom Win Subscriber Station, Siemens Scalance X200-4 P Irt Firmware, Siemens Scalance X200-4 P Irt.