Vulnerability Description
An issue was discovered in tcp_rcv() in nptcp.c in HCC embedded InterNiche 4.0.1. The TCP header processing code doesn't sanitize the value of the IP total length field (header length + data length). With a crafted IP packet, an integer overflow occurs whenever the value of the IP data length is calculated by subtracting the length of the header from the total length of the IP packet.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hcc-Embedded | Nichestack | < 4.3 |
| Siemens | Sentron 3Wl Com35 Firmware | < 1.2.0 |
| Siemens | Sentron 3Wl Com35 | - |
| Siemens | Sentron 3Wa Com190 Firmware | < 2.0.0 |
| Siemens | Sentron 3Wa Com190 | - |
Related Weaknesses (CWE)
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-789208.pdfMitigationThird Party Advisory
- https://www.forescout.com/blog/new-critical-operational-technology-vulnerabilitiMitigationThird Party Advisory
- https://www.kb.cert.org/vuls/id/608209Third Party AdvisoryUS Government Resource
- https://cert-portal.siemens.com/productcert/pdf/ssa-789208.pdfMitigationThird Party Advisory
- https://www.forescout.com/blog/new-critical-operational-technology-vulnerabilitiMitigationThird Party Advisory
- https://www.kb.cert.org/vuls/id/608209Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2021-31401?
CVE-2021-31401 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered in tcp_rcv() in nptcp.c in HCC embedded InterNiche 4.0.1. The TCP header processing code doesn't sanitize the value of the IP total length field (header length + data length). ...
How severe is CVE-2021-31401?
CVE-2021-31401 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-31401?
Check the references section above for vendor advisories and patch information. Affected products include: Hcc-Embedded Nichestack, Siemens Sentron 3Wl Com35 Firmware, Siemens Sentron 3Wl Com35, Siemens Sentron 3Wa Com190 Firmware, Siemens Sentron 3Wa Com190.