CVE-2021-31882
Description
A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303). The DHCP client application does not validate the length of the Domain Name Server IP option(s) (0x06) when processing DHCP ACK packets. This may lead to Denial-of-Service conditions. (FSMD-2021-0011)
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
The DHCP client in Capital Embedded AR Classic fails to validate DNS option length, enabling unauthenticated DoS from local network.
Vulnerability
The DHCP client application in Capital Embedded AR Classic 431-422 (all versions) and R20-11 (all versions prior to V2303) fails to validate the length of the Domain Name Server IP option (0x06) when processing DHCP ACK packets. This vulnerability stems from improper input validation in the Nucleus RTOS networking stack [2].
Exploitation
An unauthenticated attacker on the same network can send a crafted DHCP ACK packet with a malformed DNS server option to the affected device. The attacker must be able to intercept DHCP traffic or act as a rogue DHCP server. No user interaction is required. The attack exploits the lack of length validation, leading to a memory corruption condition.
Impact
Successful exploitation can cause a denial-of-service (DoS) condition, potentially rendering the device unresponsive. The attack does not require authentication and can be performed remotely from the local network, with a CVSS v3.1 base score of 9.8 [1][2].
Mitigation
As of the advisory publication date (2021-11-09), no patch is available for Capital Embedded AR Classic 431-422. For R20-11, upgrading to V2303 or later is recommended [description]. Workarounds include network segmentation and restricting DHCP server access. Siemens recommends applying general security measures for Nucleus RTOS devices [1][2].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- Range: All versions
- Range: < V2303
- Siemens/Capital Embedded AR Classic 431-422v5Range: 0
- Siemens/Capital Embedded AR Classic R20-11v5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- cert-portal.siemens.com/productcert/pdf/ssa-044112.pdfmitrex_refsource_MISC
- cert-portal.siemens.com/productcert/pdf/ssa-114589.pdfmitrex_refsource_MISC
- cert-portal.siemens.com/productcert/pdf/ssa-620288.pdfmitrex_refsource_MISC
- cert-portal.siemens.com/productcert/html/ssa-044112.htmlmitre
- cert-portal.siemens.com/productcert/html/ssa-114589.htmlmitre
- cert-portal.siemens.com/productcert/html/ssa-620288.htmlmitre
News mentions
0No linked articles in our index yet.