In Hilscher rcX RTOS versions prios to V2.1.14.1 the actual UDP packet length is not verified against the length indicated by the packet. This may lead to a denial of service of the affected device.
References
Link | Resource |
---|---|
https://cert.vde.com/de-de/advisories/vde-2021-018 | Third Party Advisory |
https://kb.hilscher.com/display/ISMS/2019-04-10+Wrong+handling+of+the+UDP+checksum | Vendor Advisory |
https://cert.vde.com/de-de/advisories/vde-2021-018 | Third Party Advisory |
https://kb.hilscher.com/display/ISMS/2019-04-10+Wrong+handling+of+the+UDP+checksum | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
History
21 Nov 2024, 05:47
Type | Values Removed | Values Added |
---|---|---|
References | () https://cert.vde.com/de-de/advisories/vde-2021-018 - Third Party Advisory | |
References | () https://kb.hilscher.com/display/ISMS/2019-04-10+Wrong+handling+of+the+UDP+checksum - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : 5.0
v3 : 8.6 |
Information
Published : 2021-05-13 14:15
Updated : 2024-11-21 05:47
NVD link : CVE-2021-20988
Mitre link : CVE-2021-20988
CVE.ORG link : CVE-2021-20988
JSON object : View
Products Affected
pepperl-fuchs
- ice1-16dio-g60l-v1d_firmware
- ice1-8iol-g30l-v1d_firmware
- ice1-8iol-s2-g60l-v1d
- ice1-8di8do-g60l-v1d
- ice1-16dio-g60l-c1-v1d
- ice1-16dio-g60l-v1d
- ice1-16dio-g60l-c1-v1d_firmware
- ice1-8di8do-g60l-c1-v1d
- ice1-8iol-g30l-v1d
- ice1-16di-g60l-v1d_firmware
- ice1-8iol-g60l-v1d
- ice1-8di8do-g60l-v1d_firmware
- ice1-8iol-s2-g60l-v1d_firmware
- ice1-8iol-g60l-v1d_firmware
- ice1-8di8do-g60l-c1-v1d_firmware
- ice1-16di-g60l-v1d
hilscher
- rcx_rtos
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer