CVE-2020-27737

CWE-125Out-of-bounds Read3 documents3 sources
Severity
6.5MEDIUM
EPSS
0.6%
top 29.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 22
Latest updateMay 24

Description

A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5.5), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.20), Nucleus NET (All versions), Nucleus ReadyStart V3 (All versions < V2017.02.3), Nucleus ReadyStart V4 (All versions < V4.1.0), Nucleus Source Code (Versions including affected DNS modules), SIMOTICS CONNECT 400 (All versions < V0.5.0.0),

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:HExploitability: 2.2 | Impact: 4.2

Affected Packages14 packages

CVEListV5siemens/apogee_pxc_compact_(bacnet)All versions < V3.5.5
CVEListV5siemens/apogee_pxc_modular_(bacnet)All versions < V3.5.5
CVEListV5siemens/talon_tc_compact_(bacnet)All versions < V3.5.5
CVEListV5siemens/talon_tc_modular_(bacnet)All versions < V3.5.5
CVEListV5siemens/apogee_pxc_compact_(p2_ethernet)All versions < V2.8.20

Patches

🔴Vulnerability Details

2
GHSA
GHSA-j94w-w786-mv9m: A vulnerability has been identified in Nucleus 4 (All versions < V42022-05-24
CVEList
CVE-2020-27737: A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V32021-04-22
CVE-2020-27737 (MEDIUM CVSS 6.5) | A vulnerability has been identified | cvebase.io