Lucene search

K
cvelistTalosCVELIST:CVE-2020-13530
HistoryDec 11, 2020 - 3:21 a.m.

CVE-2020-13530

2020-12-1103:21:01
CWE-910
talos
www.cve.org
3
denial of service
ethernet/ip server
eip stack group opener

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.003

Percentile

68.2%

A denial-of-service vulnerability exists in the Ethernet/IP server functionality of the EIP Stack Group OpENer 2.3 and development commit 8c73bf3. A large number of network requests in a small span of time can cause the running program to stop. An attacker can send a sequence of requests to trigger this vulnerability.

CNA Affected

[
  {
    "product": "EIP Stack Group",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "EIP Stack Group OpENer 2.3"
      },
      {
        "status": "affected",
        "version": "EIP Stack Group OpENer development commit 8c73bf3"
      }
    ]
  }
]

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.003

Percentile

68.2%

Related for CVELIST:CVE-2020-13530