CVE-2020-37216Improper Input Validation in Hirschmann Hios

Severity
8.7HIGHNVD
EPSS
0.0%
top 94.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 3

Description

Hirschmann HiOS devices versions prior to 08.1.00 and 07.1.01 contain a denial of service vulnerability in the EtherNet/IP stack where improper handling of packet length fields allows remote attackers to crash or hang the device. Attackers can send specially crafted UDP EtherNet/IP packets with a length value larger than the actual packet size to render the device inoperable.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Packages1 packages

CVEListV5belden/hirschmann_hios05.00.0008.0.00

🔴Vulnerability Details

2
CVEList
Hirschmann HiOS EtherNet/IP Stack Denial of Service2026-04-03
GHSA
GHSA-m685-jgfp-vmx9: Hirschmann HiOS devices versions prior to 082026-04-03
CVE-2020-37216 — Improper Input Validation | cvebase