CVE-2021-3712

Read buffer overruns processing ASN.1 strings

Published Aug 24, 2021 · Updated Apr 16, 2026

ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the string data which is terminated with a NUL (0) byte. Although not a strict requirement, ASN.1 strings that are parsed using OpenSSL's own "d2i" functions (and other similar parsing functions) as well as any string whose value has been set with the ASN1_STRING_set() function will additionally NUL terminate the byte array in the ASN1_STRING structure. However, it is possible for applications to directly construct valid ASN1_STRING structures which do not NUL terminate the byte array by directly setting the "data" and "length" fields in the ASN1_STRING array. This can also happen by using the ASN1_STRING_set0() function. Numerous OpenSSL functions that print ASN.1 data have been found to assume that the ASN1_STRING byte array will be NUL terminated, even though this is not guaranteed for strings that have been directly constructed. Where an application requests an ASN.1 structure to be printed, and where that ASN.1 structure contains ASN1_STRINGs that have been directly constructed by the application without NUL terminating the "data" field, then a read buffer overrun can occur. The same thing can also occur during name constraints processing of certificates (for example if a certificate has been directly constructed by the application instead of loading it via the OpenSSL parsing functions, and the certificate contains non NUL terminated ASN1_STRING structures). It can also occur in the X509_get1_email(), X509_REQ_get1_email() and X509_get1_ocsp() functions. If a malicious actor can cause an application to directly construct an ASN1_STRING and then process it through one of the affected OpenSSL functions then this issue could be hit. This might result in a crash (causing a Denial of Service attack). It could also result in the disclosure of private memory contents (such as private keys, or sensitive plaintext). Fixed in OpenSSL 1.1.1l (Affected 1.1.1-1.1.1k). Fixed in OpenSSL 1.0.2za (Affected 1.0.2-1.0.2y).

CVSS severityUnavailable
Unscored
EPSS probability50.44%
Next 30 days · Sep 16, 2026
Known exploitationUnconfirmed
Based on sourced intelligence
Hinoki checkNot available
Coverage for this vulnerability

See if you're affected

Explore vulnerability checks for your environment with Hinoki.

Book a demo

Summary

What happened

ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are repesented as a buffer for the string data which is terminated with a NUL (0) byte. Although not a strict requirement, ASN.1 strings that are parsed using OpenSSL's own "d2i" functions (and other similar parsing functions) as well as any string whose value has been set with the ASN1_STRING_set() function will additionally NUL terminate the byte array in the ASN1_STRING structure. However, it is possible for applications to directly construct valid ASN1_STRING structures which do not NUL terminate the byte array by directly setting the "data" and "length" fields in the ASN1_STRING array. This can also happen by using the ASN1_STRING_set0() function. Numerous OpenSSL functions that print ASN.1 data have been found to assume that the ASN1_STRING byte array will be NUL terminated, even though this is not guaranteed for strings that have been directly constructed. Where an application requests an ASN.1 structure to be printed, and where that ASN.1 structure contains ASN1_STRINGs that have been directly constructed by the application without NUL terminating the "data" field, then a read buffer overrun can occur. The same thing can also occur during name constraints processing of certificates (for example if a certificate has been directly constructed by the application instead of loading it via the OpenSSL parsing functions, and the certificate contains non NUL terminated ASN1_STRING structures). It can also occur in the X509_get1_email(), X509_REQ_get1_email() and X509_get1_ocsp() functions. If a malicious actor can cause an application to directly construct an ASN1_STRING and then process it through one of the affected OpenSSL functions then this issue could be hit. This might result in a crash (causing a Denial of Service attack). It could also result in the disclosure of private memory contents (such as private keys, or sensitive plaintext). Fixed in OpenSSL 1.1.1l (Affected 1.1.1-1.1.1k). Fixed in OpenSSL 1.0.2za (Affected 1.0.2-1.0.2y).

The record

CVE
CVE-2021-3712
Published
Aug 24, 2021
Updated
Apr 16, 2026
Vendor
Siemens
Product
SCALANCE X307-2 EEC (2x 230V)
Classifications
Unavailable
Attack vector
Unavailable
Privileges
Unavailable

Timeline

How it unfolded

  1. Aug 24, 2021CVE publishedPublication date reported by the CVE source.
  2. Apr 16, 2026Record updatedLatest update available in the CVE record.

Exploitability

Present is not the same as exploitable

Compare your product and version with the public record. A matching version still requires validation against your environment.

Is a vulnerable build present?

Compare these published version ranges with your installed build and any vendor patches.

  1. Affected versionversion=0 <V4.1.4

What conditions does exploitation require?

Attack vectorUnavailable in this record.
Required privilegesUnavailable in this record.

What is affected?

Siemens · SCALANCE X307-2 EEC (2x 230V)version=0 <V4.1.4
Siemens · SIMATIC S7-1200 CPU 1215FC DC/DC/Rlyversion=0 <V4.5.2
Siemens · SCALANCE X212-2LDversion=All versions < V5.2.6
Siemens · SCALANCE X204IRT PROversion=0 <V5.5.2
Siemens · RUGGEDCOM ROX RX1500version=0 <V2.15.0
Siemens · SINEC NMSversion=0 <V1.0 SP3
Siemens · SINUMERIK Operateversion=All versions < V4.95 SP1
Siemens · SCALANCE X308-2Mversion=0 <V4.1.4
Siemens · SCALANCE XR324-4M PoE (230V, ports on front)version=0 <V4.1.4
Siemens · SCALANCE X202-2P IRTversion=0 <V5.5.2
Siemens · SCALANCE X204-2FMversion=All versions < V5.2.6
Siemens · SCALANCE SC632-2Cversion=All versions < V2.3
Siemens · SCALANCE XR324-12M (24V, ports on front)version=0 <V4.1.4
Siemens · SCALANCE W786-2 RJ45version=0 <V6.6.0
Siemens · SCALANCE MUM856-1 (RoW)version=0 <V7.1
Siemens · RUGGEDCOM ROX RX5000version=0 <V2.15.0
Siemens · SIPLUS S7-1200 CPU 1215 AC/DC/RLYversion=0 <V4.5.2
Siemens · SCALANCE X307-3LDversion=0 <V4.1.4
Siemens · SCALANCE X302-7 EEC (24V)version=0 <V4.1.4
Siemens · SCALANCE XF204-2version=All versions < V5.2.6
Siemens · SCALANCE W786-2IA RJ45version=0 <V6.6.0
Siemens · SCALANCE XR324-4M PoE (24V, ports on rear)version=0 <V4.1.4
Siemens · SCALANCE SC622-2Cversion=All versions < V2.3
Siemens · SIPLUS S7-1200 CPU 1214C AC/DC/RLYversion=0 <V4.5.2
Siemens · SIMATIC S7-1200 CPU 1212C AC/DC/Rlyversion=0 <V4.5.2
Siemens · RUGGEDCOM ROX RX1511version=0 <V2.15.0
Siemens · SCALANCE XR324-4M EEC (2x 24V, ports on front)version=0 <V4.1.4
Siemens · SCALANCE X320-1 FEversion=0 <V4.1.4
Siemens · RUGGEDCOM ROX MX5000REversion=0 <V2.15.0
Siemens · SCALANCE X204-2TSversion=All versions < V5.2.6
Siemens · SIPLUS S7-1200 CPU 1215C DC/DC/DCversion=0 <V4.5.2
Siemens · SCALANCE W721-1 RJ45version=0 <V6.6.0
Siemens · SIPLUS S7-1200 CPU 1215FC DC/DC/DCversion=0 <V4.5.2
Siemens · SCALANCE W778-1 M12 EECversion=0 <V6.6.0
Siemens · SCALANCE X302-7 EEC (2x 230V, coated)version=0 <V4.1.4
Siemens · SCALANCE X204-2version=All versions < V5.2.6
Siemens · SCALANCE XR324-12M (230V, ports on rear)version=0 <V4.1.4
Siemens · SIPLUS S7-1200 CP 1243-1 RAILversion=All versions < V3.3.46
Siemens · SIMATIC S7-1200 CPU 1217C DC/DC/DCversion=0 <V4.5.2
Siemens · SCALANCE W761-1 RJ45version=0 <V6.6.0
Siemens · SCALANCE MUM856-1 (EU)version=0 <V7.1
Siemens · BFCClientversion=0 <V2.17
Siemens · SCALANCE X310FEversion=0 <V4.1.4
Siemens · SCALANCE X307-2 EEC (2x 24V)version=0 <V4.1.4
Siemens · SCALANCE XR324-4M EEC (24V, ports on front)version=0 <V4.1.4
Siemens · SCALANCE XR324-12M (24V, ports on rear)version=0 <V4.1.4
Siemens · SCALANCE W722-1 RJ45version=0 <V6.6.0
Siemens · SIPLUS S7-1200 CPU 1212C DC/DC/DCversion=0 <V4.5.2
Siemens · SCALANCE W748-1 RJ45version=0 <V6.6.0
Siemens · SCALANCE X206-1version=All versions < V5.2.6
Siemens · SCALANCE X204-2LDversion=All versions < V5.2.6
Siemens · RUGGEDCOM ROX RX1536version=0 <V2.15.0
Siemens · SIMATIC CP 1543-1version=All versions < V3.0.22
Siemens · SCALANCE XR324-4M PoE (24V, ports on front)version=0 <V4.1.4
Siemens · SIPLUS S7-1200 CPU 1212 AC/DC/RLYversion=0 <V4.5.2
Siemens · SCALANCE XF204IRTversion=0 <V5.5.2
Siemens · SCALANCE X302-7 EEC (2x 24V)version=0 <V4.1.4
Siemens · SIMATIC CP 1243-1version=All versions < V3.3.46
Siemens · SCALANCE X206-1LDversion=All versions < V5.2.6
Siemens · SIMATIC S7-1200 CPU 1211C DC/DC/DCversion=0 <V4.5.2
Siemens · SCALANCE W788-1 RJ45version=0 <V6.6.0
Siemens · SIMATIC S7-1200 CPU 1212FC DC/DC/Rlyversion=0 <V4.5.2
Siemens · SIMATIC CP 1542SP-1version=0 <V2.2.28
Siemens · SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on front)version=0 <V4.1.4
Siemens · SCALANCE WAM766-1 (US)version=0 <V1.2.0
Siemens · SCALANCE X202-2P IRT PROversion=0 <V5.5.2
Siemens · RUGGEDCOM RM1224 LTE(4G) NAMversion=All versions < V7.1
Siemens · RUGGEDCOM RM1224 LTE(4G) EUversion=All versions < V7.1
Siemens · SCALANCE W774-1 M12 EECversion=0 <V6.6.0
Siemens · SINEMA Remote Connect Serverversion=0 <V3.1
Siemens · SCALANCE X307-2 EEC (24V, coated)version=0 <V4.1.4
Siemens · SCALANCE X204-2LD TSversion=All versions < V5.2.6
Siemens · SCALANCE X310version=0 <V4.1.4
Siemens · SIMATIC CP 1543SP-1version=0 <V2.2.28
Siemens · SCALANCE WUM766-1version=0 <V1.2.0
Siemens · SCALANCE M874-3version=All versions < V7.1
Siemens · SCALANCE W1748-1 M12version=0 <V3.0.0
Siemens · SCALANCE X204IRTversion=0 <V5.5.2
Siemens · SCALANCE X202-2IRTversion=0 <V5.5.2
Siemens · SCALANCE X216version=All versions < V5.2.6
Siemens · SCALANCE X302-7 EEC (230V)version=0 <V4.1.4
Siemens · SCALANCE XF202-2P IRTversion=0 <V5.5.2
Siemens · SCALANCE SC642-2Cversion=All versions < V2.3
Siemens · SCALANCE X208PROversion=All versions < V5.2.6
Siemens · SCALANCE X308-2version=0 <V4.1.4
Siemens · SCALANCE W1788-2IA M12version=0 <V3.0.0
Siemens · SCALANCE XR324-12M TS (24V)version=0 <V4.1.4
Siemens · SCALANCE X302-7 EEC (2x 24V, coated)version=0 <V4.1.4
Siemens · Industrial Edge - Machine Insight Appversion=0 <*
Siemens · SCALANCE XR324-4M PoE (230V, ports on rear)version=0 <V4.1.4
Siemens · SIPLUS S7-1200 CPU 1214C DC/DC/DCversion=0 <V4.5.2
Siemens · SCALANCE X224version=All versions < V5.2.6
Siemens · SCALANCE WAM766-1version=0 <V1.2.0
Siemens · SIPLUS S7-1200 CPU 1215C AC/DC/RLYversion=0 <V4.5.2
Siemens · SCALANCE X302-7 EEC (230V, coated)version=0 <V4.1.4
Siemens · SCALANCE W778-1 M12 EEC (USA)version=0 <V6.6.0
Siemens · SCALANCE W734-1 RJ45version=0 <V6.6.0
Siemens · SIMATIC CP 1545-1version=All versions < V1.1
Siemens · SIPLUS S7-1200 CPU 1214C DC/DC/RLYversion=0 <V4.5.2
Siemens · SCALANCE M812-1 ADSL Routerversion=All versions < V7.1
Siemens · SIPLUS S7-1200 CPU 1214 DC/DC/RLYversion=0 <V4.5.2
Siemens · RUGGEDCOM ROX RX1512version=0 <V2.15.0
Siemens · SIMATIC Process Historian OPC UA Serverversion=0 <V2020 SP1
Siemens · SCALANCE X208version=All versions < V5.2.6
Siemens · SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on rear)version=0 <V4.1.4
Siemens · SIMATIC CP 1242-7 V2version=All versions < V3.3.46
Siemens · Industrial Edge - PROFINET IO Connectorversion=All versions < V1.1.1
Siemens · SCALANCE XR324-4M EEC (24V, ports on rear)version=0 <V4.1.4
Siemens · SCALANCE X201-3P IRT PROversion=0 <V5.5.2
Siemens · SIPLUS S7-1200 CPU 1215 DC/DC/DCversion=0 <V4.5.2
Siemens · SCALANCE X302-7 EEC (24V, coated)version=0 <V4.1.4
Siemens · SIMATIC S7-1200 CPU 1211C AC/DC/Rlyversion=0 <V4.5.2
Siemens · SCALANCE X307-3version=0 <V4.1.4
Siemens · SCALANCE M826-2 SHDSL-Routerversion=All versions < V7.1
Siemens · SCALANCE M816-1 ADSL Routerversion=All versions < V7.1
Siemens · SCALANCE W788-2 M12version=0 <V6.6.0
Siemens · SCALANCE X307-2 EEC (24V)version=0 <V4.1.4
Siemens · SIMATIC S7-1200 CPU 1214C AC/DC/Rlyversion=0 <V4.5.2
Siemens · SCALANCE M876-3 (ROK)version=All versions < V7.1
Siemens · SIPLUS S7-1200 CPU 1214C DC/DC/DC RAILversion=0 <V4.5.2
Siemens · SCALANCE W788-2 M12 EECversion=0 <V6.6.0
Siemens · SCALANCE X308-2LH+version=0 <V4.1.4
Siemens · RUGGEDCOM ROX RX1510version=0 <V2.15.0
Siemens · SIPLUS NET CP 1242-7 V2version=All versions < V3.3.46
Siemens · SCALANCE X308-2M PoEversion=0 <V4.1.4
Siemens · SCALANCE X307-2 EEC (230V, coated)version=0 <V4.1.4
Siemens · SIPLUS S7-1200 CPU 1214FC DC/DC/RLYversion=0 <V4.5.2
Siemens · SCALANCE M876-3version=All versions < V7.1
Siemens · SCALANCE XF201-3P IRTversion=0 <V5.5.2
Siemens · SIMATIC S7-1200 CPU 1212FC DC/DC/DCversion=0 <V4.5.2
Siemens · SCALANCE XR324-4M EEC (2x 24V, ports on rear)version=0 <V4.1.4
Siemens · SIMATIC PCS neo Administration Consoleversion=0 <V3.1.1
Siemens · SCALANCE WAM766-1 EECversion=0 <V1.2.0
Siemens · SIMATIC CP 1243-8 IRCversion=All versions < V3.3.46
Siemens · SCALANCE X302-7 EEC (2x 230V)version=0 <V4.1.4
Siemens · SIMATIC S7-1200 CPU 1212C DC/DC/DCversion=0 <V4.5.2
Siemens · SCALANCE XF208version=All versions < V5.2.6
Siemens · SCALANCE XF204-2BA IRTversion=0 <V5.5.2
Siemens · SIPLUS S7-1200 CPU 1214 AC/DC/RLYversion=0 <V4.5.2
Siemens · SIPLUS S7-1200 CPU 1215 DC/DC/RLYversion=0 <V4.5.2
Siemens · SIPLUS S7-1200 CPU 1212C AC/DC/RLYversion=0 <V4.5.2
Siemens · SIPLUS S7-1200 CPU 1212 DC/DC/RLYversion=0 <V4.5.2
Siemens · SCALANCE M804PBversion=All versions < V7.1
Siemens · SIMATIC S7-1200 CPU 1211C DC/DC/Rlyversion=0 <V4.5.2
Siemens · SCALANCE XF204version=All versions < V5.2.6
Siemens · SIMATIC CP 1243-7 LTE USversion=All versions < V3.3.46
Siemens · SIMATIC S7-1200 CPU 1215C AC/DC/Rlyversion=0 <V4.5.2
Siemens · SCALANCE W774-1 RJ45 (USA)version=0 <V6.6.0
Siemens · SCALANCE WAM766-1 EEC (US)version=0 <V1.2.0
Siemens · SIPLUS NET CP 1543-1version=All versions < V3.0.22
OpenSSL Project · OpenSSLversion=Fixed in OpenSSL 1.0.2za (Affected 1.0.2-1.0.2y); version=Fixed in OpenSSL 1.1.1l (Affected 1.1.1-1.1.1k)
Siemens · SIPLUS S7-1200 CPU 1214FC DC/DC/DCversion=0 <V4.5.2
Siemens · SCALANCE X308-2M TSversion=0 <V4.1.4
Siemens · SIMATIC S7-1200 CPU 1215FC DC/DC/DCversion=0 <V4.5.2
Siemens · SCALANCE W774-1 RJ45version=0 <V6.6.0
Siemens · SCALANCE X307-2 EEC (230V)version=0 <V4.1.4
Siemens · SIMATIC S7-1200 CPU 1215C DC/DC/DCversion=0 <V4.5.2
Siemens · SCALANCE W1788-2 M12version=0 <V3.0.0
Siemens · SCALANCE W786-2 SFPversion=0 <V6.6.0
Siemens · RUGGEDCOM ROX RX1524version=0 <V2.15.0
Siemens · SCALANCE SC636-2Cversion=All versions < V2.3
Siemens · SCALANCE W748-1 M12version=0 <V6.6.0
Siemens · SCALANCE XR324-4M EEC (100-240VAC/60-250VDC, ports on rear)version=0 <V4.1.4
Siemens · SINEMA Serverversion=0 <*
Siemens · SCALANCE X307-2 EEC (2x 230V, coated)version=0 <V4.1.4
Siemens · SCALANCE XR324-4M EEC (2x 100-240VAC/60-250VDC, ports on front)version=0 <V4.1.4
Siemens · SIMATIC S7-1200 CPU 1212C DC/DC/RLYversion=0 <V4.5.2
Siemens · SCALANCE X306-1LD FEversion=0 <V4.1.4
Siemens · SCALANCE XR324-12M (230V, ports on front)version=0 <V4.1.4
Siemens · SIMATIC S7-1200 CPU 1215C DC/DC/Rlyversion=0 <V4.5.2
Siemens · RUGGEDCOM ROX RX1501version=0 <V2.15.0
Siemens · SCALANCE W738-1 M12version=0 <V6.6.0
Siemens · SCALANCE M876-4 (NAM)version=All versions < V7.1
Siemens · SIPLUS ET 200SP CP 1543SP-1 ISEC TX RAILversion=0 <V2.2.28
Siemens · SCALANCE MUM853-1 (EU)version=0 <V7.1
Siemens · SCALANCE W788-1 M12version=0 <V6.6.0
Siemens · SCALANCE X304-2FEversion=0 <V4.1.4
Siemens · SIPLUS S7-1200 CP 1243-1version=All versions < V3.3.46
Siemens · SCALANCE W786-1 RJ45version=0 <V6.6.0
Siemens · SCALANCE X308-2LDversion=0 <V4.1.4
Siemens · SIPLUS S7-1200 CPU 1212C DC/DC/DC RAILversion=0 <V4.5.2
Siemens · SCALANCE W734-1 RJ45 (USA)version=0 <V6.6.0
Siemens · SIMATIC S7-1200 CPU 1214C DC/DC/DCversion=0 <V4.5.2
Siemens · SIMATIC S7-1200 CPU 1214C DC/DC/Rlyversion=0 <V4.5.2
Siemens · SIMATIC S7-1200 CPU 1214FC DC/DC/DCversion=0 <V4.5.2
Siemens · SCALANCE X307-2 EEC (2x 24V, coated)version=0 <V4.1.4
Siemens · SIMATIC CP 1243-7 LTE EUversion=All versions < V3.3.46
Siemens · SCALANCE W1788-2 EEC M12version=0 <V3.0.0
Siemens · SCALANCE WUM766-1 (USA)version=0 <V1.2.0
Siemens · SCALANCE X201-3P IRTversion=0 <V5.5.2
Siemens · SCALANCE X320-1-2LD FEversion=0 <V4.1.4
Siemens · SCALANCE X408-2version=0 <V4.1.4
Siemens · SCALANCE XF206-1version=All versions < V5.2.6
Siemens · SIMATIC S7-1200 CPU 1214FC DC/DC/Rlyversion=0 <V4.5.2
Siemens · SCALANCE W1788-1 M12version=0 <V3.0.0
Siemens · SIPLUS ET 200SP CP 1543SP-1 ISECversion=0 <V2.2.28
Siemens · SCALANCE XR324-4M PoE TS (24V, ports on front)version=0 <V4.1.4
Siemens · SCALANCE S615 LAN-Routerversion=All versions < V7.1
Siemens · SCALANCE W788-2 RJ45version=0 <V6.6.0
Siemens · RUGGEDCOM ROX RX1400version=0 <V2.15.0
Siemens · SCALANCE SC646-2Cversion=All versions < V2.3
Siemens · RUGGEDCOM ROX MX5000version=0 <V2.15.0
Siemens · SCALANCE X200-4P IRTversion=0 <V5.5.2
Siemens · SCALANCE M876-4 (EU)version=All versions < V7.1
Siemens · SCALANCE X212-2version=All versions < V5.2.6
Siemens · TIA Administratorversion=0 <V1.0.7
Siemens · SIPLUS NET SCALANCE X308-2version=0 <V4.1.4
Siemens · SCALANCE W778-1 M12version=0 <V6.6.0
Siemens · SCALANCE M874-2version=All versions < V7.1

Published CVSS scores

No CVSS assessment is available in this record.

CVSS describes severity. EPSS estimates exploitation probability.

Attacks

What attackers are doing with it

Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.

Daily unique IPsNo honeypot observations are available for this CVE in the selected window.

No observations available

Sep 10, 2026Sep 16, 2026
Latest reporting daySep 16, 2026
Latest daily unique IPsUnavailable
Prior 30-day averageUnavailable
SourceShadowserver honeypots (KEV)
VectorUnavailable
PrivilegesUnavailable
Known exploitationUnconfirmed
Public exploitUnconfirmed

Weakness, pattern, technique

No sourced classifications are available.

Public exploit references

No public exploit references are available in this record.

Labels summarize the accepted research assessment. They do not indicate a test against your environment.

Technologies

Your stack

See the directory against your own environment.

Your stack

Check the software in your environment

Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.

Book a demo