CVE-2021-37182 - CVE House
Back to Database
Status published High CVE-2021-37182

A vulnerability has been identified in SCALANCE XM408-4C (All versions...

Vulnerability Description

A vulnerability has been identified in SCALANCE XM408-4C (All versions < V6.5), SCALANCE XM408-4C (L3 int.) (All versions < V6.5), SCALANCE XM408-8C (All versions < V6.5), SCALANCE XM408-8C (L3 int.) (All versions < V6.5), SCALANCE XM416-4C (All versions < V6.5), SCALANCE XM416-4C (L3 int.) (All versions < V6.5), SCALANCE XR524-8C, 1x230V (All versions < V6.5), SCALANCE XR524-8C, 1x230V (L3 int.) (All versions < V6.5), SCALANCE XR524-8C, 24V (All versions < V6.5), SCALANCE XR524-8C, 24V (L3 int.) (All versions < V6.5), SCALANCE XR524-8C, 2x230V (All versions < V6.5), SCALANCE XR524-8C, 2x230V (L3 int.) (All versions < V6.5), SCALANCE XR526-8C, 1x230V (All versions < V6.5), SCALANCE XR526-8C, 1x230V (L3 int.) (All versions < V6.5), SCALANCE XR526-8C, 24V (All versions < V6.5), SCALANCE XR526-8C, 24V (L3 int.) (All versions < V6.5), SCALANCE XR526-8C, 2x230V (All versions < V6.5), SCALANCE XR526-8C, 2x230V (L3 int.) (All versions < V6.5), SCALANCE XR528-6M (All versions < V6.5), SCALANCE XR528-6M (2HR2) (All versions < V6.5), SCALANCE XR528-6M (2HR2, L3 int.) (All versions < V6.5), SCALANCE XR528-6M (L3 int.) (All versions < V6.5), SCALANCE XR552-12M (All versions < V6.5), SCALANCE XR552-12M (2HR2) (All versions < V6.5), SCALANCE XR552-12M (2HR2) (All versions < V6.5), SCALANCE XR552-12M (2HR2, L3 int.) (All versions < V6.5). The OSPF protocol implementation in affected devices fails to verify the checksum and length fields in the OSPF LS Update messages. An unauthenticated remote attacker could exploit this vulnerability to cause interruptions in the network by sending specially crafted OSPF packets. Successful exploitation requires OSPF to be enabled on an affected device.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-37182

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

SCALANCE XM408-4C, SCALANCE XM408-4C (L3 int.), SCALANCE XM408-8C, SCALANCE XM408-8C (L3 int.), SCALANCE XM416-4C, SCALANCE XM416-4C (L3 int.), SCALANCE XR524-8C, 1x230V, SCALANCE XR524-8C, 1x230V (L3 int.), SCALANCE XR524-8C, 24V, SCALANCE XR524-8C, 24V (L3 int.), SCALANCE XR524-8C, 2x230V, SCALANCE XR524-8C, 2x230V (L3 int.), SCALANCE XR526-8C, 1x230V, SCALANCE XR526-8C, 1x230V (L3 int.), SCALANCE XR526-8C, 24V, SCALANCE XR526-8C, 24V (L3 int.), SCALANCE XR526-8C, 2x230V, SCALANCE XR526-8C, 2x230V (L3 int.), SCALANCE XR528-6M, SCALANCE XR528-6M (2HR2), SCALANCE XR528-6M (2HR2, L3 int.), SCALANCE XR528-6M (L3 int.), SCALANCE XR552-12M, SCALANCE XR552-12M (2HR2), SCALANCE XR552-12M (2HR2, L3 int.)
Vulnerable Versions:
All versions < V6.5

Timeline

Official Publish: June 14th, 2022
Last Modified: August 4th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.