Vulnerability Description
An issue was discovered in Contiki through 3.0. An Out-of-Bounds Read vulnerability exists in the uIP TCP/IP Stack component when calculating the checksums for IP packets in upper_layer_chksum in net/ipv4/uip.c.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Uip Project | Uip | <= 1.0 |
| Contiki-Os | Contiki | <= 3.0 |
| Open-Iscsi Project | Open-Iscsi | <= 2.1.12 |
| Siemens | Sentron 3Va Com100 Firmware | < 4.4.1 |
| Siemens | Sentron 3Va Com100 | - |
| Siemens | Sentron 3Va Com800 Firmware | < 4.4.1 |
| Siemens | Sentron 3Va Com800 | - |
| Siemens | Sentron Pac3200 Firmware | < 2.4.7 |
| Siemens | Sentron Pac3200 | - |
| Siemens | Sentron Pac4200 Firmware | < 2.3.0 |
| Siemens | Sentron Pac4200 | - |
Related Weaknesses (CWE)
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-541018.pdfPatchThird Party Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-20-343-01Third Party AdvisoryUS Government Resource
- https://www.kb.cert.org/vuls/id/815128Third Party AdvisoryUS Government Resource
- https://cert-portal.siemens.com/productcert/pdf/ssa-541018.pdfPatchThird Party Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-20-343-01Third Party AdvisoryUS Government Resource
- https://www.kb.cert.org/vuls/id/815128Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2020-13987?
CVE-2020-13987 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered in Contiki through 3.0. An Out-of-Bounds Read vulnerability exists in the uIP TCP/IP Stack component when calculating the checksums for IP packets in upper_layer_chksum in net/...
How severe is CVE-2020-13987?
CVE-2020-13987 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-13987?
Check the references section above for vendor advisories and patch information. Affected products include: Uip Project Uip, Contiki-Os Contiki, Open-Iscsi Project Open-Iscsi, Siemens Sentron 3Va Com100 Firmware, Siemens Sentron 3Va Com100.