CVE-2020-13987Out-of-bounds Read in Siemens Sentron 3VA Com100 Firmware

Severity
7.5HIGHNVD
EPSS
0.2%
top 59.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 11
Latest updateJul 27

Description

An issue was discovered in Contiki through 3.0. An Out-of-Bounds Read vulnerability exists in the uIP TCP/IP Stack component when calculating the checksums for IP packets in upper_layer_chksum in net/ipv4/uip.c.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages9 packages

Patches

🔴Vulnerability Details

3
OSV
open-iscsi vulnerabilities2023-07-27
GHSA
GHSA-g438-vfc9-cq65: An issue was discovered in Contiki through 32022-05-24
OSV
CVE-2020-13987: An issue was discovered in Contiki through 32020-12-11

📋Vendor Advisories

5
Ubuntu
Open-iSCSI vulnerabilities2023-07-27
CISA ICS
Siemens TCP/IP Stack Vulnerabilities–AMNESIA:33 in SENTRON PAC / 3VA Devices (Update C)2021-08-10
CISA ICS
Multiple Embedded TCP/IP Stacks2020-12-09
Red Hat
Open-iSCSI: OOB read in checksum calculation in uIP2020-12-09
Debian
CVE-2020-13987: open-iscsi - An issue was discovered in Contiki through 3.0. An Out-of-Bounds Read vulnerabil...2020

🕵️Threat Intelligence

1
Tenable
AMNESIA:33: Researchers Disclose 33 Vulnerabilities Across Four Open Source TCP/IP Libraries2020-12-09