Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-35683


An issue was discovered in HCC Nichestack 3.0. The code that parses ICMP packets relies on an unchecked value of the IP payload size (extracted from the IP header) to compute the ICMP checksum. When the IP payload size is set to be smaller than the size of the IP header, the ICMP checksum computation function may read out of bounds, causing a Denial-of-Service.


Published

2021-08-19T12:15:07.353

Last Modified

2024-11-21T05:27:50.590

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-125

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application hcc-embedded nichestack 3.0 Yes
Operating System siemens 7km9300-0ae02-0aa0_firmware < 3.0.4 Yes
Hardware siemens 7km9300-0ae02-0aa0 - No

References