« Back to list

CVE-2021-25671

Status: ModifiedMedium (4.3)—

A vulnerability has been identified in RWG1.M12 (All versions < V1.16.16), RWG1.M12D (All versions < V1.16.16), RWG1.M8 (All versions < V1.16.16). Sending specially crafted ARP packets to an affected device could cause a partial denial-of-service, preventing the device to operate normally. A restart is needed to restore normal operations.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (3)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2021-25671",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.3,
          "accessVector": "ADJACENT_NETWORK",
          "vectorString": "AV:A/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.5,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "productcert@siemens.com",
      "affectedData": [
        {
          "vendor": "Siemens",
          "product": "RWG1.M12",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V1.16.16"
            }
          ]
        },
        {
          "vendor": "Siemens",
          "product": "RWG1.M12D",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V1.16.16"
            }
          ]
        },
        {
          "vendor": "Siemens",
          "product": "RWG1.M8",
          "versions": [
            {
              "status": "affected",
              "version": "All versions < V1.16.16"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-07-13T11:15:09.370",
  "references": [
    {
      "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-448291.pdf",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "productcert@siemens.com"
    },
    {
      "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-448291.pdf",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "productcert@siemens.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-770"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability has been identified in RWG1.M12 (All versions < V1.16.16), RWG1.M12D (All versions < V1.16.16), RWG1.M8 (All versions < V1.16.16). Sending specially crafted ARP packets to an affected device could cause a partial denial-of-service, preventing the device to operate normally. A restart is needed to restore normal operations."
    },
    {
      "lang": "es",
      "value": "Se ha identificado una vulnerabilidad en RWG1.M12 (Todas las versiones anteriores a V1.16.16), RWG1.M12D (Todas las versiones anteriores a V1.16.16), RWG1.M8 (Todas las versiones anteriores a V1.16.16). El envío de paquetes ARP especialmente diseñados hacia un dispositivo afectado podría causar una denegación de servicio parcial, previniendo que el dispositivo opere normalmente. Es necesario reiniciar el dispositivo para restablecer el funcionamiento normal"
    }
  ],
  "lastModified": "2026-06-17T03:42:19.927",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:siemens:rwg1.m12_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CA9F44E3-B373-484D-AA90-B1B6DEF10D60",
              "versionEndExcluding": "1.16.16"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:siemens:rwg1.m12:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "85DABF7F-79E4-4DDA-AB8E-7BA5556868EB"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:siemens:rwg1.m12d_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E2187D88-2FDB-423A-8DC3-F9D3A862458B",
              "versionEndExcluding": "1.16.16"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:siemens:rwg1.m12d:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "BA59A914-1E04-4465-ADB5-AC20583C4360"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:siemens:rwg1.m8_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BC82DD96-236B-4140-A682-2A2D24918F30",
              "versionEndExcluding": "1.16.16"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:siemens:rwg1.m8:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F23D72C3-DFDA-412D-8C7C-61AB6580C1A7"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "productcert@siemens.com"
}