CVE-2021-27391 - CVE House
Back to Database
Status published Unknown CVE-2021-27391

A vulnerability has been identified in APOGEE MBC (PPC) (P2...

Vulnerability Description

A vulnerability has been identified in APOGEE MBC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE MEC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE PXC Compact (BACnet) (All versions < V3.5.3), APOGEE PXC Compact (P2 Ethernet) (All versions >= V2.8), APOGEE PXC Modular (BACnet) (All versions < V3.5.3), APOGEE PXC Modular (P2 Ethernet) (All versions >= V2.8), TALON TC Compact (BACnet) (All versions < V3.5.3), TALON TC Modular (BACnet) (All versions < V3.5.3). The web server of affected devices lacks proper bounds checking when parsing the Host parameter in HTTP requests, which could lead to a buffer overflow. An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary code on the device with root privileges.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-27391

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

APOGEE MBC (PPC) (P2 Ethernet), APOGEE MEC (PPC) (P2 Ethernet), APOGEE PXC Compact (BACnet), APOGEE PXC Compact (P2 Ethernet), APOGEE PXC Modular (BACnet), APOGEE PXC Modular (P2 Ethernet), TALON TC Compact (BACnet), TALON TC Modular (BACnet)
Vulnerable Versions:
All versions >= V2.6.3, All versions < V3.5.3, All versions >= V2.8

Timeline

Official Publish: September 14th, 2021
Last Modified: April 23rd, 2025
Added to House: July 21st, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)