You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve-2021-3712
About this tag
CVE-2021-3712 is an OpenSSL vulnerability that allows out-of-bounds reads, posing a significant risk to industrial control systems. On WindowsForum.com, discussions focus on Siemens products affected by this flaw, including networking, communications, and automation devices. Siemens has released ProductCERT guidance and patches for many SKUs, but some product lines, such as parts of Industrial Edge and legacy appliances, lack planned fixes and require operator-side mitigations. The Brownfield Connectivity Client (BFCClient) is also impacted, with an urgent recommendation to update to V2.17 or later. Users share patching strategies and mitigation steps to reduce exposure in industrial environments.
Siemens and upstream OpenSSL vulnerabilities that allow out-of-bounds reads — tracked under CVE-2021-3712 — remain a live operational risk across dozens of Siemens industrial networking, communications, and automation products; Siemens has published ProductCERT guidance and fixes for many...
Siemens’ Brownfield Connectivity Client (BFCClient) is the subject of a freshly republished advisory that bundles multiple OpenSSL-related flaws into a single operational risk for industrial environments—vulnerabilities that can be remotely triggered, permit memory disclosure or application...