CVE-2021-25677

MEDIUM

APOGEE PXC Compact/BACnet, Modular/BACnet, Nucleus NET, ReadyStart ...

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5.5), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.20), Nucleus NET (All versions), Nucleus ReadyStart V3 (All versions < V2017.02.3), Nucleus ReadyStart V3 (All versions < V2017.02.4), Nucleus ReadyStart V4 (All versions < V4.1.0), Nucleus Source Code (Versions including affected DNS modules), SIMOTICS CONNECT 400 (All versions < V0.5.0.0), SIMOTICS CONNECT 400 (All versions >= V0.5.0.0 < V1.0.0.0), TALON TC Compact (BACnet) (All versions < V3.5.5), TALON TC Modular (BACnet) (All versions < V3.5.5). The DNS client does not properly randomize DNS transaction IDs. That could allow an attacker to poison the DNS cache or spoof DNS resolving.

Scores

CVSS v3 5.3
EPSS 0.0039
EPSS Percentile 59.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-330
Status published
Products (5)
siemens/nucleus_net
siemens/nucleus_readystart_v3 < 2017.02.4
siemens/nucleus_readystart_v4 < 4.1.0
siemens/nucleus_source_code
siemens/simotics_connect_400_firmware 0.5.0.0
Published Apr 22, 2021
Tracked Since Feb 18, 2026