CVE-2021-42018 describes a critical heap overflow vulnerability (CWE-122, CWE-787) affecting numerous Siemens RUGGEDCOM industrial networking devices. This flaw stems from insufficient size checking during memory allocation within a third-party component, potentially leading to the allocation of a smaller buffer than requested. Rated with a CVSS score of 9.8 (CRITICAL), this vulnerability can be exploited remotely without authentication or user interaction (AV:N/AC:L/PR:N/UI:N), allowing an attacker to achieve high impact on confidentiality, integrity, and availability (C:H/I:H/A:H). The FAUCET Risk Score is 79/100, indicating a significant threat. Currently, there is no evidence of active exploitation (KEV: No), nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness despite its critical severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:siemens:ruggedcom_ros:*:*:*:*:*:*:*:* | ||
< 5.6.0CPE matchmatch criteria | cpe:2.3:o:siemens:ruggedcom_ros:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.