CVE-2021-27393

MEDIUM

Nucleus NET, ReadyStart V3 <V2013.08, Source Code - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in Nucleus NET (All versions), Nucleus ReadyStart V3 (All versions < V2013.08), Nucleus Source Code (Versions including affected DNS modules). The DNS client does not properly randomize UDP port numbers of DNS requests. That could allow an attacker to poison the DNS cache or spoof DNS resolving.

Scores

CVSS v3 5.3
EPSS 0.0022
EPSS Percentile 44.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-330
Status published
Products (3)
siemens/nucleus_net
siemens/nucleus_readystart_v3 < 2013.08
siemens/nucleus_source_code
Published Apr 22, 2021
Tracked Since Feb 18, 2026