CVE-2020-15795
published 2021-04-22CVE-2020-15795: A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE…
PriorityP353high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
6.37%
92.9th percentile
A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5.5), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.20), Nucleus NET (All versions < V5.2), Nucleus Source Code (Versions including affected DNS modules), TALON TC Compact (BACnet) (All versions < V3.5.5), TALON TC Modular (BACnet) (All versions < V3.5.5). The DNS domain name label parsing functionality does not properly validate the names in DNS-responses. The parsing of malformed responses could result in a write past the end of an allocated structure. An attacker with a privileged position in the network could leverage this vulnerability to execute code in the context of the current process or cause a denial-of-service condition.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| paloalto | pan-os | — | — |
| paloalto | prisma_sd | — | — |
| siemens | apogee_pxc_compact | — | — |
| siemens | apogee_pxc_compact | — | — |
| siemens | apogee_pxc_modular | — | — |
| siemens | apogee_pxc_modular | — | — |
| siemens | nucleus_net | < 5.2 | 5.2 |
| siemens | nucleus_net | — | — |
| siemens | nucleus_source_code | — | — |
| siemens | talon_tc_compact | — | — |
| siemens | talon_tc_modular | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2021-0003 Informational: Impact of the NAME:WRECK DNS vulnerabilities
vendor_paloalto·2021-05-10·CVSS 9.8
[CRITICAL] PAN-SA-2021-0003 Informational: Impact of the NAME:WRECK DNS vulnerabilities
PAN-SA-2021-0003 Informational: Impact of the NAME:WRECK DNS vulnerabilities
The Palo Alto Networks Product Security Assurance team evaluated the NAME:WRECK DNS vulnerabilities impacting multiple TCP/IP software stack implementations. PAN-OS software and Prisma SD-WAN (CloudGenix) devices do not utilize the IPNet, Nucleus NET, FreeBSD, or NetX TCP/IP software stacks related to these vulnerabilities. As a result, there is no known security impact for these vulnerabilities in PAN-OS software or Prisma SD-WAN (CloudGenix) devices. CVE Summary CVE-2016-20009 This vulnerability in the IPNet TCP/IP stack does not impact PAN-OS software or Prisma SD-WAN (CloudGenix) devices. CVE-2020-15795 This vulnerability in the Nucleus NET TCP/IP stack does not impact PAN-OS software or Prisma SD-WAN (CloudG
CISA ICS
Siemens Nucleus Products DNS Module (Update A)
cisa_ics·2021-04-13·CVSS 8.1
[HIGH] Siemens Nucleus Products DNS Module (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens Nucleus Products DNS Module (Update A)
Last RevisedNovember 11, 2021
Alert CodeICSA-21-103-04
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.1
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
--------- Begin Update A Part 1 of 3 ---------
- Equipment: Nucleus NET, Nucleus Source Code, Capital VSTAR
--------- End Update A Part 1 of 3 ---------
- Vulnerabilities: Out-of-bounds Write, Use of Out-of-Range Pointer Offset
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the original advisory titled ICSA-21-103-04 Siemens Nucleus Products D
GHSA
GHSA-cw98-4v34-2rc8: A vulnerability has been identified in Nucleus NET (All versions < V5
ghsa_unreviewed·2022-05-24
CVE-2020-15795 [HIGH] CWE-787 GHSA-cw98-4v34-2rc8: A vulnerability has been identified in Nucleus NET (All versions < V5
A vulnerability has been identified in Nucleus NET (All versions < V5.2), Nucleus RTOS (versions including affected DNS modules), Nucleus Source Code (versions including affected DNS modules), VSTAR (versions including affected DNS modules). The DNS domain name label parsing functionality does not properly validate the names in DNS-responses. The parsing of malformed responses could result in a write past the end of an allocated structure. An attacker with a privileged position in the network could leverage this vulnerability to execute code in the context of the current process or cause a denial-of-service condition.
No detection rules found.
No public exploits indexed.
2021-04-22
Published