LiveActive security incident?Get immediate response
CVE Record

CVE-2021-31400: An issue was discovered in tcp_pulloutofband() in tcp_in.c in HCC embedded InterNiche 4.0.1.

An issue was discovered in tcp_pulloutofband() in tcp_in.c in HCC embedded InterNiche 4.0.1. The TCP out-of-band urgent-data processing function invokes a panic function if the pointer to the end of the out-of-band data points outside of the TCP segment's data. If the panic function hadn't a trap invocation removed, it will enter an infinite loop and therefore cause DoS (continuous loop or a device reset).

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

CVE-2021-31400 can cause affected embedded devices using HCC embedded InterNiche 4.0.1 to stop working or reset when handling malformed TCP urgent data. The business concern is availability, especially for operational technology or network-connected embedded systems. The provided sources do not confirm active exploitation or a specific patch.

Executive priority

Prioritize discovery over emergency action unless exposed affected devices are confirmed. The risk is operational disruption, not data theft, but downtime in OT or embedded environments can still be material. Vendor confirmation is the key next step.

Technical view

The flaw is in tcp_pulloutofband() in tcp_in.c. During TCP out-of-band urgent-data processing, an end pointer outside the TCP segment data can trigger panic handling. If trap invocation was removed, panic may become an infinite loop, causing denial of service through continuous looping or device reset.

Likely exposure

Exposure is likely limited to products that embed HCC embedded InterNiche 4.0.1 and accept TCP traffic. The source bundle does not identify specific device models, vendors, CPEs, or deployment profiles, so asset-level confirmation is required.

Exploitation context

The bundle describes a denial-of-service condition reachable through TCP urgent-data processing. It does not cite public exploitation, weaponized proof-of-concept activity, or CISA KEV listing. Treat internet- or OT-network reachable embedded devices as higher concern until vendor impact is confirmed.

Researcher notes

The CVE record names HCC embedded InterNiche 4.0.1 and tcp_pulloutofband() but provides no CVSS, CWE, CPE, patch version, or exploit evidence. Avoid broad product claims without vendor mapping. Focus research on firmware provenance, stack versioning, and reachability.

Mitigation direction

  • Inventory embedded devices and confirm whether they use HCC embedded InterNiche 4.0.1.
  • Check HCC and device-vendor advisories for confirmed affected firmware and fixes.
  • Apply vendor-provided firmware or stack updates when available.
  • Restrict untrusted TCP access to affected embedded devices.
  • Segment OT and management networks from general user and internet traffic.
  • Monitor for unexplained resets, hangs, or availability loss on candidate devices.

Validation and detection

  • Map products using InterNiche or NicheStack components in firmware SBOMs or vendor documentation.
  • Ask vendors directly whether CVE-2021-31400 affects deployed device firmware.
  • Review network exposure for devices accepting TCP connections from untrusted networks.
  • Check operational logs for repeated resets or hangs after malformed traffic events.
  • Prioritize validation on safety-critical, remote, or hard-to-reboot embedded assets.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-31400 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.