CVE-2021-31895 is a critical vulnerability affecting numerous Siemens RUGGEDCOM devices across multiple product lines and versions. The flaw lies in the DHCP client's failure to properly sanitize incoming DHCP packets, leading to a memory overwrite vulnerability. This could allow an unauthenticated remote attacker to achieve remote code execution (RCE) with a CVSS score of 9.8 (Critical). The attack vector is network-based with low attack complexity, requiring no user interaction or privileges. A successful exploit could result in complete compromise of confidentiality, integrity, and availability of the affected device. Currently, there is no evidence of active exploitation in the wild, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Despite the lack of public exploits, the vulnerability has garnered significant community discussion, indicating awareness and potential interest among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.3.7CPE matchmatch criteria | cpe:2.3:o:siemens:ruggedcom_ros_i800:*:*:*:*:*:*:*:* | ||
< 4.3.7CPE matchmatch criteria | cpe:2.3:o:siemens:ruggedcom_ros_i801:*:*:*:*:*:*:*:* | ||
< 4.3.7CPE matchmatch criteria | cpe:2.3:o:siemens:ruggedcom_ros_i802:*:*:*:*:*:*:*:* | ||
< 4.3.7CPE matchmatch criteria | cpe:2.3:o:siemens:ruggedcom_ros_i803:*:*:*:*:*:*:*:* | ||
< 4.3.7CPE matchmatch criteria | cpe:2.3:o:siemens:ruggedcom_ros_m969:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.