{"id": "CVE-2020-28393", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 7.1, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:C", "authentication": "NONE", "integrityImpact": "NONE", "accessComplexity": "MEDIUM", "availabilityImpact": "COMPLETE", "confidentialityImpact": "NONE"}, "acInsufInfo": false, "impactScore": 6.9, "baseSeverity": "HIGH", "obtainAllPrivilege": false, "exploitabilityScore": 8.6, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV31": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 7.5, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "NONE"}, "impactScore": 3.6, "exploitabilityScore": 3.9}]}, "published": "2021-05-12T14:15:11.083", "references": [{"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-116379.pdf", "tags": ["Vendor Advisory"], "source": "productcert@siemens.com"}, {"url": "https://us-cert.cisa.gov/ics/advisories/icsa-21-131-10", "tags": ["Third Party Advisory", "US Government Resource"], "source": "productcert@siemens.com"}, {"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-116379.pdf", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}, {"url": "https://us-cert.cisa.gov/ics/advisories/icsa-21-131-10", "tags": ["Third Party Advisory", "US Government Resource"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Secondary", "source": "productcert@siemens.com", "description": [{"lang": "en", "value": "CWE-682"}]}], "descriptions": [{"lang": "en", "value": "An unauthenticated remote attacker could create a permanent denial-of-service condition by sending specially crafted OSPF packets. Successful exploitation requires OSPF to be enabled on an affected device on the SCALANCE XM-400, XR-500 (All versions prior to v6.4)."}, {"lang": "es", "value": "Se ha identificado una vulnerabilidad en SCALANCE XM-400 Family (todas las versiones anteriores a V6.4), SCALANCE XR-500 Family (todas las versiones anteriores a V6.4). La implementaci\u00f3n del protocolo OSPF en los dispositivos afectados maneja incorrectamente el n\u00famero de campos LSA en combinaci\u00f3n con otros campos modificados. Un atacante remoto no autenticado podr\u00eda crear una condici\u00f3n de Denegaci\u00f3n de Servicio permanente al enviar paquetes OSPF especialmente dise\u00f1ados. Una explotaci\u00f3n con \u00e9xito requiere que OSPF est\u00e9 habilitado en un dispositivo afectado"}], "lastModified": "2024-11-21T05:22:42.740", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:siemens:scalance_xm-400_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E40058B3-3726-4F6A-AB41-7679487639F2", "versionEndExcluding": "6.4"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:siemens:scalance_xm-400:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "798E900F-5EF9-4B39-B8C2-79FAE659E7F5"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:siemens:scalance_xr524_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "66B18697-4508-465B-AB56-A64DF601F8E4", "versionEndExcluding": "6.4"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:siemens:scalance_xr524:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "7DEEA300-16C3-4FEE-88A8-674DE2AEEC95"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:siemens:scalance_xr526_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1DC81BDD-1426-4BF3-AB8B-D050EC9E44EB", "versionEndExcluding": "6.4"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:siemens:scalance_xr526:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "756A07F8-4F9F-4A76-942E-82CB92216943"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:siemens:scalance_xr528_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "70411378-1EEE-401A-A7C9-A88299215F82", "versionEndExcluding": "6.4"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:siemens:scalance_xr528:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "FDE5E54D-FFED-4C2C-B89D-E085E61D44E4"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:siemens:scalance_xr552_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8DA7378E-5E6A-4541-B078-AB7E8CDC0E3E", "versionEndExcluding": "6.4"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:siemens:scalance_xr552:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "AB16A0BE-5AF3-4168-B755-D023E497A35F"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:siemens:scalance_xm416-4c_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B98F706F-1994-464F-A7BC-01E476EA699F", "versionEndExcluding": "6.4"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:siemens:scalance_xm416-4c:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "F9102A41-5812-4014-BC07-E571E815ED49"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:siemens:scalance_xm408-8c_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3A2826CF-A6AD-4FC8-8CE7-F1B5ACAA7451", "versionEndExcluding": "6.4"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:siemens:scalance_xm408-8c:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "7096DBA5-95BB-44D7-B7CA-B1845C87F70E"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:siemens:scalance_xm408-4c_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "192095A3-5A69-4B45-8A01-8A563C1ED8BA", "versionEndExcluding": "6.4"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:siemens:scalance_xm408-4c:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "2AA81823-013F-4990-B62D-86C404F04BCB"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:siemens:scalance_xm416-4c_l3_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E34C5BF4-3761-4762-B0DE-3C4235C8B04C", "versionEndExcluding": "6.4"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:siemens:scalance_xm416-4c_l3:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "86A2A766-9046-484F-9D49-4A1F4F0F96A4"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:siemens:scalance_xm408-8c_l3_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E21E3308-2C77-4233-8827-3F0613121015", "versionEndExcluding": "6.4"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:siemens:scalance_xm408-8c_l3:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "78562689-B494-4500-9725-B418F1EC3CAB"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:siemens:scalance_xm408-4c_l3_firmware:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "96CF5766-E762-4329-BDCC-6833CD90BC4E", "versionEndExcluding": "6.4"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:siemens:scalance_xm408-4c_l3:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "B2FB222B-0414-4A1E-8BBD-6470CDB3BFF8"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "productcert@siemens.com"}