CVE-2020-13529
published 2021-05-10CVE-2020-13529: An exploitable denial-of-service vulnerability exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cause a server running the DHCP client to…
PriorityP426medium6.1CVSS 3.1
AVAACHPRNUINSCCNINAH
EPSS
1.40%
69.4th percentile
An exploitable denial-of-service vulnerability exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cause a server running the DHCP client to be vulnerable to a DHCP ACK spoofing attack. An attacker can forge a pair of FORCERENEW and DCHP ACK packets to reconfigure the server.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | systemd | < systemd 249.4-2 (bookworm) | systemd 249.4-2 (bookworm) |
| fedoraproject | fedora | — | — |
| systemd_project | systemd | — | — |
| systemd_project | systemd | — | — |
| systemd_project | systemd | >= 0 < 249.4-2 | 249.4-2 |
| systemd_project | systemd | >= 0 < 249.4-2 | 249.4-2 |
| systemd_project | systemd | >= 0 < 249.4-2 | 249.4-2 |
| systemd_project | systemd | >= 0 < 237-3ubuntu10.49 | 237-3ubuntu10.49 |
| systemd_project | systemd | >= 0 < 245.4-4ubuntu3.10 | 245.4-4ubuntu3.10 |
| systemd_project | systemd | >= 0 < 229-4ubuntu21.31+esm1 | 229-4ubuntu21.31+esm1 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv3.06.1MEDIUMCVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
nvdv2.02.9LOWAV:A/AC:M/Au:N/C:N/I:N/A:P
osv6.1MEDIUM
vendor_debian6.1LOW
vendor_redhat6.1MEDIUM
vendor_ubuntu6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Ubuntu
systemd vulnerabilities
vendor_ubuntu·2021-07-20·CVSS 6.1
CVE-2020-13529 [MEDIUM] systemd vulnerabilities
Title: systemd vulnerabilities
Summary: Several security issues were fixed in systemd.
USN-5013-1 fixed several vulnerabilities in systemd. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that systemd incorrectly handled certain mount paths. A
local attacker could possibly use this issue to cause systemd to crash,
resulting in a denial of service. (CVE-2021-33910)
Mitchell Frank discovered that systemd incorrectly handled DHCP FORCERENEW
packets. A remote attacker could possibly use this issue to reconfigure
servers. (CVE-2020-13529)
Instructions: After a standard system update you need to reboot your computer to make all
the necessary changes.
Ubuntu
systemd vulnerabilities
vendor_ubuntu·2021-07-20·CVSS 6.1
CVE-2020-13529 [MEDIUM] systemd vulnerabilities
Title: systemd vulnerabilities
Summary: Several security issues were fixed in systemd.
It was discovered that systemd incorrectly handled certain mount paths. A
local attacker could possibly use this issue to cause systemd to crash,
resulting in a denial of service. (CVE-2021-33910)
Mitchell Frank discovered that systemd incorrectly handled DHCP FORCERENEW
packets. A remote attacker could possibly use this issue to reconfigure
servers. (CVE-2020-13529)
Instructions: After a standard system update you need to reboot your computer to make all
the necessary changes.
Red Hat
systemd: DHCP FORCERENEW authentication not implemented can cause a system running the DHCP client to have its network reconfigured
vendor_redhat·2021-04-26·CVSS 6.1
CVE-2020-13529 [MEDIUM] CWE-306 systemd: DHCP FORCERENEW authentication not implemented can cause a system running the DHCP client to have its network reconfigured
systemd: DHCP FORCERENEW authentication not implemented can cause a system running the DHCP client to have its network reconfigured
An exploitable denial-of-service vulnerability exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cause a server running the DHCP client to be vulnerable to a DHCP ACK spoofing attack. An attacker can forge a pair of FORCERENEW and DCHP ACK packets to reconfigure the server.
An exploitable denial of service vulnerability exists in systemd which does not fully implement RFC3203, as it does not support authentication of FORCERENEW packets. A specially crafted DHCP FORCERENEW packet can cause a system, running the DHCP client, to be vulnerable to a DHCP ACK spoofing attack. An attacker can forge a pair of FORCERENEW and DCHPACK packets to rec
Debian
CVE-2020-13529: systemd - An exploitable denial-of-service vulnerability exists in Systemd 245. A speciall...
vendor_debian·2020·CVSS 6.1
CVE-2020-13529 [MEDIUM] CVE-2020-13529: systemd - An exploitable denial-of-service vulnerability exists in Systemd 245. A speciall...
An exploitable denial-of-service vulnerability exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cause a server running the DHCP client to be vulnerable to a DHCP ACK spoofing attack. An attacker can forge a pair of FORCERENEW and DCHP ACK packets to reconfigure the server.
Scope: local
bookworm: resolved (fixed in 249.4-2)
bullseye: open
forky: resolved (fixed in 249.4-2)
sid: resolved (fixed in 249.4-2)
trixie: resolved (fixed in 249.4-2)
GHSA
GHSA-44p7-qpr4-rgvf: An exploitable denial-of-service vulnerability exists in Systemd 245
ghsa_unreviewed·2022-05-24
CVE-2020-13529 [MEDIUM] CWE-290 GHSA-44p7-qpr4-rgvf: An exploitable denial-of-service vulnerability exists in Systemd 245
An exploitable denial-of-service vulnerability exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cause a server running the DHCP client to be vulnerable to a DHCP ACK spoofing attack. An attacker can forge a pair of FORCERENEW and DCHP ACK packets to reconfigure the server.
OSV
systemd vulnerabilities
osv·2021-07-20·CVSS 6.1
CVE-2021-33910 [MEDIUM] systemd vulnerabilities
systemd vulnerabilities
USN-5013-1 fixed several vulnerabilities in systemd. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that systemd incorrectly handled certain mount paths. A
local attacker could possibly use this issue to cause systemd to crash,
resulting in a denial of service. (CVE-2021-33910)
Mitchell Frank discovered that systemd incorrectly handled DHCP FORCERENEW
packets. A remote attacker could possibly use this issue to reconfigure
servers. (CVE-2020-13529)
OSV
systemd vulnerabilities
osv·2021-07-20·CVSS 6.1
CVE-2021-33910 [MEDIUM] systemd vulnerabilities
systemd vulnerabilities
It was discovered that systemd incorrectly handled certain mount paths. A
local attacker could possibly use this issue to cause systemd to crash,
resulting in a denial of service. (CVE-2021-33910)
Mitchell Frank discovered that systemd incorrectly handled DHCP FORCERENEW
packets. A remote attacker could possibly use this issue to reconfigure
servers. (CVE-2020-13529)
OSV
CVE-2020-13529: An exploitable denial-of-service vulnerability exists in Systemd 245
osv·2021-05-10·CVSS 6.1
CVE-2020-13529 [MEDIUM] CVE-2020-13529: An exploitable denial-of-service vulnerability exists in Systemd 245
An exploitable denial-of-service vulnerability exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cause a server running the DHCP client to be vulnerable to a DHCP ACK spoofing attack. An attacker can forge a pair of FORCERENEW and DCHP ACK packets to reconfigure the server.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2021/08/04/2http://www.openwall.com/lists/oss-security/2021/08/17/3http://www.openwall.com/lists/oss-security/2021/09/07/3https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/42TMJVNYRY65B4QCJICBYOEIVZV3KUYI/https://security.gentoo.org/glsa/202107-48https://security.netapp.com/advisory/ntap-20210625-0005/https://talosintelligence.com/vulnerability_reports/TALOS-2020-1142http://www.openwall.com/lists/oss-security/2021/08/04/2http://www.openwall.com/lists/oss-security/2021/08/17/3http://www.openwall.com/lists/oss-security/2021/09/07/3https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/42TMJVNYRY65B4QCJICBYOEIVZV3KUYI/https://security.gentoo.org/glsa/202107-48https://security.netapp.com/advisory/ntap-20210625-0005/https://talosintelligence.com/vulnerability_reports/TALOS-2020-1142
2021-05-10
Published