peter bassill · operator
$ cve CVE-2021-27391 JSON

CVE-2021-27391

9.8
CRITICAL · CVSS 3.1 · EPSS 3.4% (pctl 88)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A vulnerability has been identified in APOGEE MBC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE MEC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE PXC Compact (BACnet) (All versions < V3.5.3), APOGEE PXC Compact (P2 Ethernet) (All versions >= V2.8), APOGEE PXC Modular (BACnet) (All versions < V3.5.3), APOGEE PXC Modular (P2 Ethernet) (All versions >= V2.8), TALON TC Compact (BACnet) (All versions < V3.5.3), TALON TC Modular (BACnet) (All versions < V3.5.3). The web server of affected devices lacks proper bounds checking when parsing the Host parameter in HTTP requests, which could lead to a buffer overflow. An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary code on the device with root privileges.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.37% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-120
On CISA KEVno
Public exploitnone known
Published2021-09-14
Last modified2026-06-17

Affected (16)

VendorProduct
siemensapogee mbc \(ppc\) \(p2 ethernet\)
siemensapogee mbc \(ppc\) \(p2 ethernet\) firmware
siemensapogee mec \(ppc\) \(p2 ethernet\)
siemensapogee mec \(ppc\) \(p2 ethernet\) firmware
siemensapogee pxc bacnet automation controller
siemensapogee pxc bacnet automation controller firmware
siemensapogee pxc compact \(p2 ethernet\)
siemensapogee pxc compact \(p2 ethernet\) firmware
siemensapogee pxc modular \(bacnet\)
siemensapogee pxc modular \(bacnet\) firmware
siemensapogee pxc modular \(p2 ethernet\)
siemensapogee pxc modular \(p2 ethernet\) firmware
siemenstalon tc compact \(bacnet\)
siemenstalon tc compact \(bacnet\) firmware
siemenstalon tc modular \(bacnet\)
siemenstalon tc modular \(bacnet\) firmware

References

→ the Explorer  ·  watch your stack  ·  NVD