CVE-2021-31344
Description
A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions), SIMOTICS CONNECT 400 (All versions < V0.5.0.0), SIMOTICS CONNECT 400 (All versions < V1.0.0.0). ICMP echo packets with fake IP options allow sending ICMP echo reply messages to arbitrary hosts on the network. (FSMD-2021-0004)
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An ICMP spoofing vulnerability in Nucleus NET TCP/IP stack allows sending echo replies to arbitrary hosts, enabling network-based reflection/amplification attacks.
Vulnerability
CVE-2021-31344, part of the NUCLEUS:13 set, resides in the ICMP handling of the Nucleus NET TCP/IP stack used in multiple Siemens products [1], [2]. The vulnerability allows an attacker to craft ICMP echo request packets with fake IP options; the vulnerable stack then sends ICMP echo reply messages to arbitrary hosts on the network [1], [2]. Affected products include Capital Embedded AR Classic 431-422 (all versions), Capital Embedded AR Classic R20-11 (versions < V2303), PLUSCONTROL 1st Gen (all versions), SIMOTICS CONNECT 400 (versions < V0.5.0.0 and versions < V1.0.0.0), and potentially others listed in the referenced advisories [1], [4].
Exploitation
An attacker on the same network segment can send a specially crafted ICMP echo request packet with manipulated IP options to a vulnerable device [1], [2]. The attacker does not need authentication. The vulnerable device processes the packet and generates an ICMP echo reply destined for the arbitrary host address injected in the malicious request, effectively causing the device to participate in a reflected traffic attack [1], [2].
Impact
Successful exploitation enables the attacker to use the vulnerable device as an amplifier to send ICMP echo reply traffic to a target of their choice on the network [1], [2]. This can result in traffic flooding, potentially leading to denial-of-service conditions or network resource exhaustion. The impact is limited to the local network segment unless the device can route the replies further [1].
Mitigation
Siemens has released updates for some affected products: for SIMOTICS CONNECT 400, update to V0.5.0.0 or later (for versions < V0.5.0.0) or to V1.0.0.0 or later (for versions < V1.0.0.0) [1], [4]. For PLUSCONTROL 1st Gen (all versions) no remediation is currently planned; Siemens recommends isolating those devices in a separate LAN segment and applying general security best practices [3]. For other products, refer to the respective advisory for specific workarounds [1], [2].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
7< V0.5.0.0; < V1.0.0.0+ 1 more
- (no CPE)range: < V0.5.0.0; < V1.0.0.0
- (no CPE)range: All versions < V1.0.0.0
- Range: All versions
- Range: < V2303
- Siemens/Capital Embedded AR Classic 431-422v5Range: 0
- Siemens/Capital Embedded AR Classic R20-11v5Range: 0
- Siemens/PLUSCONTROL 1st Genv5Range: All versions
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- cert-portal.siemens.com/productcert/pdf/ssa-044112.pdfmitrex_refsource_MISC
- cert-portal.siemens.com/productcert/pdf/ssa-114589.pdfmitrex_refsource_MISC
- cert-portal.siemens.com/productcert/pdf/ssa-223353.pdfmitrex_refsource_MISC
- cert-portal.siemens.com/productcert/pdf/ssa-620288.pdfmitrex_refsource_MISC
- cert-portal.siemens.com/productcert/pdf/ssa-845392.pdfmitrex_refsource_MISC
- cert-portal.siemens.com/productcert/html/ssa-044112.htmlmitre
- cert-portal.siemens.com/productcert/html/ssa-114589.htmlmitre
- cert-portal.siemens.com/productcert/html/ssa-223353.htmlmitre
- cert-portal.siemens.com/productcert/html/ssa-620288.htmlmitre
- cert-portal.siemens.com/productcert/html/ssa-845392.htmlmitre
News mentions
0No linked articles in our index yet.