CVE-2021-27391

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
14/09/2021
Last modified:
23/04/2025

Description

A vulnerability has been identified in APOGEE MBC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE MEC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE PXC Compact (BACnet) (All versions = V2.8), APOGEE PXC Modular (BACnet) (All versions = V2.8), TALON TC Compact (BACnet) (All versions

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:siemens:apogee_mbc_\(ppc\)_\(p2_ethernet\)_firmware:*:*:*:*:*:*:*:* 2.6.3 (including)
cpe:2.3:h:siemens:apogee_mbc_\(ppc\)_\(p2_ethernet\):*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:apogee_mec_\(ppc\)_\(p2_ethernet\)_firmware:*:*:*:*:*:*:*:* 2.6.3 (including)
cpe:2.3:h:siemens:apogee_mec_\(ppc\)_\(p2_ethernet\):*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:apogee_pxc_bacnet_automation_controller_firmware:*:*:*:*:*:*:*:* 3.5.3 (excluding)
cpe:2.3:h:siemens:apogee_pxc_bacnet_automation_controller:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:apogee_pxc_compact_\(p2_ethernet\)_firmware:*:*:*:*:*:*:*:* 2.8 (including)
cpe:2.3:h:siemens:apogee_pxc_compact_\(p2_ethernet\):*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:apogee_pxc_modular_\(bacnet\)_firmware:*:*:*:*:*:*:*:* 3.5.3 (excluding)
cpe:2.3:h:siemens:apogee_pxc_modular_\(bacnet\):*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:apogee_pxc_modular_\(p2_ethernet\)_firmware:*:*:*:*:*:*:*:* 2.8 (including)
cpe:2.3:h:siemens:apogee_pxc_modular_\(p2_ethernet\):*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:talon_tc_compact_\(bacnet\)_firmware:*:*:*:*:*:*:*:* 3.5.3 (excluding)
cpe:2.3:h:siemens:talon_tc_compact_\(bacnet\):*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:talon_tc_modular_\(bacnet\)_firmware:*:*:*:*:*:*:*:* 3.5.3 (excluding)