← Vulnerability feed

Vulnerability record · CVE-2021-25676 · published 15 March 2021

CVE-2021-25676: Siemens ruggedcom rm1224 firmware improper restriction of authentication attempts vulnerability

Siemens · Ruggedcom Rm1224 Firmware

A vulnerability has been identified in RUGGEDCOM RM1224 (V6.3), SCALANCE M-800 (V6.3), SCALANCE S615 (V6.3), SCALANCE SC-600 (All Versions >= V2.1 and < V2.1.3). Multiple failed SSH authentication attempts could trigger a temporary Denial-of-Service under certain conditions. When triggered, the device will reboot automatically.

7.5 CVSS 3.1 High EPSS 1.3% · top 30.9% CWE-307 · Improper restriction of authentication attempts
7.5CVSS 3.1 base score, v2 5.0
1.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A vulnerability has been identified in RUGGEDCOM RM1224 (V6.3), SCALANCE M-800 (V6.3), SCALANCE S615 (V6.3), SCALANCE SC-600 (All Versions >= V2.1 and < V2.1.3). Multiple failed SSH authentication attempts could trigger a temporary Denial-of-Service under certain conditions. When triggered, the device will reboot automatically.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-25676 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-14491dnsmasq heap buffer overflow via crafted DNS responsednsmasq before 2.78 contains a heap-based buffer overflow (CWE-787 out-of-bounds write) triggered by a crafted DNS response. Because dnsmasq is widel…EPSS 85%analysed9.1CVE-2022-36323Siemens scalance m-800 firmware injection vulnerabilityAffected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject …EPSS 1.7%8.8CVE-2021-25667Siemens ruggedcom rm1224 firmware stack-based buffer overflow vulnerabilityA vulnerability has been identified in RUGGEDCOM RM1224 (All versions >= V4.3 and < V6.4), SCALANCE M-800 (All versions >= V4.3 and < V6.4), SCALANCE…EPSS 0.86%8.7CVE-2020-28400Siemens dk standard ethernet controller evaluation kit firmware allocation without limits vulnerabilityAffected devices contain a vulnerability that allows an unauthenticated attacker to trigger a denial of service condition. The vulnerability can be t…EPSS 1.9%8.6CVE-2024-50572Siemens ruggedcom rm1224 lte\(4g\) eu firmware injection vulnerabilityA vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-…EPSS 0.67%8.6CVE-2024-50557Siemens ruggedcom rm1224 lte\(4g\) eu firmware improper input validation vulnerabilityA vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-…EPSS 0.90%8.6CVE-2022-31766Siemens ruggedcom rm1224 firmware improper input validation vulnerabilityA vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.1.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK610…EPSS 1.1%7.5CVE-2022-36324Siemens scalance m-800 firmware allocation without limits vulnerabilityAffected devices do not properly handle the renegotiation of SSL/TLS parameters. This could allow an unauthenticated remote attacker to bypass the TC…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2021-25676), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.