An issue was discovered in Wind River VxWorks before 6.5. There is a possible heap overflow in dhcp client.
Conclusion & alert: CVE-2021-29998 is rated High Risk (65.4/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 0.81%). Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-15 | 0.60% | 0.81% | +0.21% |
| 2 | 2026-01-26 | 0.72% | 0.60% | -0.12% |
| 3 | 2025-11-21 | — | 0.72% | — |
Full EPSS history (24 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 7.5 | 2.0 | HIGH |
|
10.0 | 6.4 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| windriver | vxworks | < 6.5 | cpe:2.3:o:windriver:vxworks:*:*:*:*:*:*:*:* |
| siemens | ruggedcom_win_subscriber_station_firmware | — | cpe:2.3:o:siemens:ruggedcom_win_subscriber_station_firmware:*:*:*:*:*:*:*:* |
| siemens | scalance_x200-4_p_irt_firmware | — | cpe:2.3:o:siemens:scalance_x200-4_p_irt_firmware:*:*:*:*:*:*:*:* |
| siemens | scalance_x201-3p_irt_firmware | — | cpe:2.3:o:siemens:scalance_x201-3p_irt_firmware:*:*:*:*:*:*:*:* |
| siemens | scalance_x201-3p_irt_pro_firmware | — | cpe:2.3:o:siemens:scalance_x201-3p_irt_pro_firmware:*:*:*:*:*:*:*:* |
| siemens | scalance_x202-2_irt_firmware | — | cpe:2.3:o:siemens:scalance_x202-2_irt_firmware:*:*:*:*:*:*:*:* |
| siemens | scalance_x202-2p_irt_firmware | — | cpe:2.3:o:siemens:scalance_x202-2p_irt_firmware:*:*:*:*:*:*:*:* |
| siemens | scalance_x202-2p_irt_pro_firmware | — | cpe:2.3:o:siemens:scalance_x202-2p_irt_pro_firmware:*:*:*:*:*:*:*:* |
| siemens | scalance_x204_irt_firmware | — | cpe:2.3:o:siemens:scalance_x204_irt_firmware:*:*:*:*:*:*:*:* |
| siemens | scalance_x204_irt_pro_firmware | — | cpe:2.3:o:siemens:scalance_x204_irt_pro_firmware:*:*:*:*:*:*:*:* |
| siemens | scalance_x204-2_firmware | — | cpe:2.3:o:siemens:scalance_x204-2_firmware:*:*:*:*:*:*:*:* |
| siemens | scalance_x204-2fm_firmware | — | cpe:2.3:o:siemens:scalance_x204-2fm_firmware:*:*:*:*:*:*:*:* |
| siemens | scalance_x204-2ld_firmware | — | cpe:2.3:o:siemens:scalance_x204-2ld_firmware:*:*:*:*:*:*:*:* |
| siemens | scalance_x204-2ld_ts_firmware | — | cpe:2.3:o:siemens:scalance_x204-2ld_ts_firmware:*:*:*:*:*:*:*:* |
| siemens | scalance_x204-2ts_firmware | — | cpe:2.3:o:siemens:scalance_x204-2ts_firmware:*:*:*:*:*:*:*:* |
| siemens | scalance_x206-1_firmware | — | cpe:2.3:o:siemens:scalance_x206-1_firmware:*:*:*:*:*:*:*:* |
| siemens | scalance_x206-1ld_firmware | — | cpe:2.3:o:siemens:scalance_x206-1ld_firmware:*:*:*:*:*:*:*:* |
| siemens | scalance_x208_firmware | — | cpe:2.3:o:siemens:scalance_x208_firmware:*:*:*:*:*:*:*:* |
| siemens | scalance_x208_pro_firmware | — | cpe:2.3:o:siemens:scalance_x208_pro_firmware:*:*:*:*:*:*:*:* |
| siemens | scalance_x212-2_firmware | — | cpe:2.3:o:siemens:scalance_x212-2_firmware:*:*:*:*:*:*:*:* |
| siemens | scalance_x212-2ld_firmware | — | cpe:2.3:o:siemens:scalance_x212-2ld_firmware:*:*:*:*:*:*:*:* |
| siemens | scalance_x216_firmware | — | cpe:2.3:o:siemens:scalance_x216_firmware:*:*:*:*:*:*:*:* |
| siemens | scalance_x224_firmware | — | cpe:2.3:o:siemens:scalance_x224_firmware:*:*:*:*:*:*:*:* |
| siemens | scalance_x300_firmware | — | cpe:2.3:o:siemens:scalance_x300_firmware:*:*:*:*:*:*:*:* |
| siemens | scalance_x408_firmware | — | cpe:2.3:o:siemens:scalance_x408_firmware:*:*:*:*:*:*:*:* |
| siemens | scalance_xf201-3p_irt_firmware | — | cpe:2.3:o:siemens:scalance_xf201-3p_irt_firmware:*:*:*:*:*:*:*:* |
| siemens | scalance_xf202-2p_irt_firmware | — | cpe:2.3:o:siemens:scalance_xf202-2p_irt_firmware:*:*:*:*:*:*:*:* |
| siemens | scalance_xf204_firmware | — | cpe:2.3:o:siemens:scalance_xf204_firmware:*:*:*:*:*:*:*:* |
| siemens | scalance_xf204_irt_firmware | — | cpe:2.3:o:siemens:scalance_xf204_irt_firmware:*:*:*:*:*:*:*:* |
| siemens | scalance_xf204-2_firmware | — | cpe:2.3:o:siemens:scalance_xf204-2_firmware:*:*:*:*:*:*:*:* |
| siemens | scalance_xf204-2ba_irt_firmware | — | cpe:2.3:o:siemens:scalance_xf204-2ba_irt_firmware:*:*:*:*:*:*:*:* |
| siemens | scalance_xf206-1_firmware | — | cpe:2.3:o:siemens:scalance_xf206-1_firmware:*:*:*:*:*:*:*:* |
| siemens | scalance_xf208_firmware | — | cpe:2.3:o:siemens:scalance_xf208_firmware:*:*:*:*:*:*:*:* |
| siemens | simatic_rf_181_eip_firmware | — | cpe:2.3:o:siemens:simatic_rf_181_eip_firmware:*:*:*:*:*:*:*:* |
| siemens | simatic_rf_182c_firmware | — | cpe:2.3:o:siemens:simatic_rf_182c_firmware:*:*:*:*:*:*:*:* |
| siemens | sinamics_perfect_harmony_gh180_firmware | >= 2015, < 2022 | cpe:2.3:o:siemens:sinamics_perfect_harmony_gh180_firmware:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://cert-portal.siemens.com/productcert/pdf/ssa-560465.pdf | Third Party Advisory |
| https://cert-portal.siemens.com/productcert/pdf/ssa-910883.pdf | Third Party Advisory |
| https://support2.windriver.com/index.php?page=security-notices | Vendor Advisory |
| https://us-cert.cisa.gov/ics/advisories/icsa-21-194-12 | Third Party Advisory US Government Resource |