PatchSiren cyber security CVE debrief
CVE-2021-3712 Siemens CVE debrief
CVE-2021-3712 is an OpenSSL ASN.1 string handling issue that can cause a read buffer overrun when code assumes ASN.1 strings are NUL-terminated but they were directly constructed without a trailing NUL. The reported impact includes application crashes and possible disclosure of private memory contents. In the Siemens/CISA advisory corpus, the issue is tied to multiple SCALANCE wireless products and is addressed by updating to V6.6.0 or later.
- Vendor
- Siemens
- Product
- SCALANCE W721-1 RJ45 (6GK5721-1FC00-0AA0)
- CVSS
- HIGH 7.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-08-12
- Original CVE updated
- 2025-08-12
- Advisory published
- 2025-08-12
- Advisory updated
- 2025-08-12
Who should care
Operators and maintainers of the affected Siemens SCALANCE wireless devices, OT/ICS security teams, and any application owners that rely on OpenSSL to print or process ASN.1 data from directly constructed ASN1_STRING objects.
Technical summary
OpenSSL’s ASN.1 printing and related routines can read past the end of an ASN1_STRING buffer when the code expects a terminating NUL byte that is not guaranteed for directly constructed strings or strings created with ASN1_STRING_set0(). The advisory notes that this can affect ASN.1 printing, certificate name-constraint processing, X509_get1_email(), X509_REQ_get1_email(), and X509_get1_ocsp(). The corpus states that affected OpenSSL releases were 1.1.1 through 1.1.1k and 1.0.2 through 1.0.2y, with fixes in 1.1.1l and 1.0.2za; Siemens remediates the impacted SCALANCE product set by moving to V6.6.0 or later.
Defensive priority
High for affected SCALANCE deployments. Prioritize remediation because the flaw can lead to denial of service and potential memory disclosure, and the advisory maps it to multiple industrial wireless products.
Recommended defensive actions
- Confirm whether any listed Siemens SCALANCE models are deployed in your environment and whether they are running versions earlier than V6.6.0.
- Apply Siemens’ remediation to update affected devices to V6.6.0 or later using the linked ProductCERT guidance.
- Treat the advisory as a memory-safety exposure in OpenSSL-dependent workflows and verify whether any local applications directly construct ASN1_STRING objects or use ASN1_STRING_set0().
- Reduce operational exposure for affected devices by segmenting OT networks and limiting unnecessary access to management interfaces.
- Monitor for unexpected crashes or abnormal behavior in systems that process certificates or ASN.1 data until remediation is complete.
Evidence notes
The source corpus is a CISA CSAF republication of Siemens ProductCERT advisory SSA-019200 (ICSA-26-111-07), first published on 2026-04-14 and republished on 2026-04-21. The advisory text explicitly describes a read buffer overrun in OpenSSL ASN.1 handling, cites potential crash and private-memory disclosure, and lists the Siemens SCALANCE product set plus the V6.6.0-or-later fix. The vendor mapping in the supplied metadata is marked low confidence/needs review, so the product association should be treated as advisory-backed but not independently validated here.
Sources and references
Verified primary and authoritative sources
-
CVE-2021-3712 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2021-3712
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2021-3712 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-3712
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-111-07.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-019200.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-019200.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-111-07
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.