Medium severity6.5NVD Advisory· Published Mar 21, 2022· Updated Jun 17, 2026
CVE-2021-45117
CVE-2021-45117
Description
The OPC autogenerated ANSI C stack stubs (in the NodeSets) do not handle all error cases. This can lead to a NULL pointer dereference.
Affected products
9cpe:2.3:a:siemens:simatic_net_pc:14:-:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:siemens:simatic_net_pc:14:-:*:*:*:*:*:*
- cpe:2.3:a:siemens:simatic_net_pc:15:-:*:*:*:*:*:*
- cpe:2.3:a:siemens:simatic_net_pc:16:-:*:*:*:*:*:*
- cpe:2.3:a:siemens:simatic_net_pc:17:-:*:*:*:*:*:*
- cpe:2.3:a:siemens:sitop_manager:-:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:telecontrol_server_basic:3.0:*:*:*:*:*:*:*
- OPC/OPC autogenerated ANSI C stack stubsdescription
Patches
Vulnerability mechanics
References
3- cert-portal.siemens.com/productcert/pdf/ssa-285795.pdfnvdPatchThird Party Advisory
- files.opcfoundation.org/SecurityBulletins/OPC%20Foundation%20Security%20Bulletin%20CVE-2021-45117.pdfnvdPatchVendor Advisory
- www.youtube.com/watchnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.