Vulnerability

CVE-2021-31889

Component: CELLULAR
Location: FIRMWARE
A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions < V3.5.4), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.19), APOGEE PXC Modular (BACnet) (All versions < V3.5.4), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.19), Capital VSTAR (All versions with enabled Ethernet options), Desigo PXC00-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC00-U (All versions >= V2.3 and < V6.30.016), Desigo PXC001-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC100-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC12-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC128-U (All versions >= V2.3 and < V6.30.016), Desigo PXC200-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC22-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC22.1-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC36.1-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC50-E.D (All versions >= V2.3 and < V6.30.016), Desigo PXC64-U (All versions >= V2.3 and < V6.30.016), Desigo PXM20-E (All versions >= V2.3 and < V6.30.016), Nucleus NET (All versions), Nucleus ReadyStart V3 (All versions < V2017.02.4), Nucleus Source Code (All versions), PLUSCONTROL 1st Gen (All versions), SIMOTICS CONNECT 400 (All versions < V0.5.0.0), TALON TC Compact (BACnet) (All versions < V3.5.4), TALON TC Modular (BACnet) (All versions < V3.5.4). Malformed TCP packets with a corrupted SACK option leads to Information Leaks and Denial-of-Service conditions. (FSMD-2021-0015)

Impact

Severity (Manufact.)

HIGH

Severity (NIST)

9.1

Severity (Android)

N/A

Chipsets

27

Devices

844

Affected Hardware

NameAlso known asManufacturer
MT6739
MediaTek
MT6762
Helio P22
MediaTek
MT6765
Helio P35
MediaTek
MT6771
Helio P60
MediaTek
MT6768
Helio P65
MediaTek
MT6769T
Helio G80
MediaTek
MT6769Z
Helio G85
MediaTek
MT6781
Helio G96
MediaTek
MT6833
Dimensity 6020
Dimensity 700
MediaTek
MT6873
Dimensity 800
MediaTek
27 of 27 row(s) shown.

Rows per page

Page 1 of 3

Timeline

Introduced (est):
Jul 1, 2017
Reported:
Unknown
Advisory Published:
Jan 3, 2022
CVE Published:
Nov 9, 2021
Android Patch Level:
Jan 2022
For more information and a detailed analysis of the data presented on this website, please see our paper, to be presented at NDSS'25.
Follow us on Twitter