HIGH · 7.5

CVE-2020-28400

Affected devices contain a vulnerability that allows an unauthenticated attacker to trigger a denial of service condition. The vulnerability can be triggered if a large amount of DCP reset packets are...

Vulnerability Description

Affected devices contain a vulnerability that allows an unauthenticated attacker to trigger a denial of service condition. The vulnerability can be triggered if a large amount of DCP reset packets are sent to the device.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
SiemensDk Standard Ethernet Controller Evaluation Kit FirmwareAll versions
SiemensDk Standard Ethernet Controller Evaluation Kit-
SiemensEk-Ertec 200 Evaulation Kit FirmwareAll versions
SiemensEk-Ertec 200 Evaulation Kit-
SiemensEk-Ertec 200P Evaluation Kit Firmware< 4.7
SiemensEk-Ertec 200P Evaluation Kit-
SiemensRuggedcom Rm1224 Firmware< 6.4
SiemensRuggedcom Rm1224-
SiemensScalance M-800 Firmware< 6.4
SiemensScalance M-800-
SiemensScalance S615 Firmware< 6.4
SiemensScalance S615-
SiemensScalance W700 FirmwareAll versions
SiemensScalance W700-
SiemensScalance W1700 FirmwareAll versions
SiemensScalance W1700-
SiemensScalance X200-4 P Irt Firmware< 5.5.0
SiemensScalance X200-4 P Irt-
SiemensScalance X201-3P Irt Firmware< 5.5.0
SiemensScalance X201-3P Irt-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-28400?

CVE-2020-28400 is a vulnerability with a CVSS score of 7.5 (HIGH). Affected devices contain a vulnerability that allows an unauthenticated attacker to trigger a denial of service condition. The vulnerability can be triggered if a large amount of DCP reset packets are...

How severe is CVE-2020-28400?

CVE-2020-28400 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-28400?

Check the references section above for vendor advisories and patch information. Affected products include: Siemens Dk Standard Ethernet Controller Evaluation Kit Firmware, Siemens Dk Standard Ethernet Controller Evaluation Kit, Siemens Ek-Ertec 200 Evaulation Kit Firmware, Siemens Ek-Ertec 200 Evaulation Kit, Siemens Ek-Ertec 200P Evaluation Kit Firmware.