CVE-2021-25671
Estado: ModificadaMedia (4.3)—
Se ha identificado una vulnerabilidad en RWG1.M12 (Todas las versiones anteriores a V1.16.16), RWG1.M12D (Todas las versiones anteriores a V1.16.16), RWG1.M8 (Todas las versiones anteriores a V1.16.16). El envío de paquetes ARP especialmente diseñados hacia un dispositivo afectado podría causar una denegación de servicio parcial, previniendo que el dispositivo opere normalmente. Es necesario reiniciar el dispositivo para restablecer el funcionamiento normal
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.38%
- Percentil entre todas las CVEs puntuadas: 29
- Fecha de la puntuación: 9/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (3)
CWE
- CWE-770
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-25671",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 3.3,
"accessVector": "ADJACENT_NETWORK",
"vectorString": "AV:A/AC:L/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 6.5,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "productcert@siemens.com",
"affectedData": [
{
"vendor": "Siemens",
"product": "RWG1.M12",
"versions": [
{
"status": "affected",
"version": "All versions < V1.16.16"
}
]
},
{
"vendor": "Siemens",
"product": "RWG1.M12D",
"versions": [
{
"status": "affected",
"version": "All versions < V1.16.16"
}
]
},
{
"vendor": "Siemens",
"product": "RWG1.M8",
"versions": [
{
"status": "affected",
"version": "All versions < V1.16.16"
}
]
}
]
}
],
"published": "2021-07-13T11:15:09.370",
"references": [
{
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-448291.pdf",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "productcert@siemens.com"
},
{
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-448291.pdf",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "productcert@siemens.com",
"description": [
{
"lang": "en",
"value": "CWE-770"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability has been identified in RWG1.M12 (All versions < V1.16.16), RWG1.M12D (All versions < V1.16.16), RWG1.M8 (All versions < V1.16.16). Sending specially crafted ARP packets to an affected device could cause a partial denial-of-service, preventing the device to operate normally. A restart is needed to restore normal operations."
},
{
"lang": "es",
"value": "Se ha identificado una vulnerabilidad en RWG1.M12 (Todas las versiones anteriores a V1.16.16), RWG1.M12D (Todas las versiones anteriores a V1.16.16), RWG1.M8 (Todas las versiones anteriores a V1.16.16). El envío de paquetes ARP especialmente diseñados hacia un dispositivo afectado podría causar una denegación de servicio parcial, previniendo que el dispositivo opere normalmente. Es necesario reiniciar el dispositivo para restablecer el funcionamiento normal"
}
],
"lastModified": "2026-06-17T03:42:19.927",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:siemens:rwg1.m12_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CA9F44E3-B373-484D-AA90-B1B6DEF10D60",
"versionEndExcluding": "1.16.16"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:siemens:rwg1.m12:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "85DABF7F-79E4-4DDA-AB8E-7BA5556868EB"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:siemens:rwg1.m12d_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E2187D88-2FDB-423A-8DC3-F9D3A862458B",
"versionEndExcluding": "1.16.16"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:siemens:rwg1.m12d:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "BA59A914-1E04-4465-ADB5-AC20583C4360"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:siemens:rwg1.m8_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BC82DD96-236B-4140-A682-2A2D24918F30",
"versionEndExcluding": "1.16.16"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:siemens:rwg1.m8:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F23D72C3-DFDA-412D-8C7C-61AB6580C1A7"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "productcert@siemens.com"
}