Lucene search

K
cvelistTalosCVELIST:CVE-2020-13556
HistoryDec 11, 2020 - 3:13 a.m.

CVE-2020-13556

2020-12-1103:13:22
CWE-787
talos
www.cve.org
1
vulnerability
ethernet/ip server
remote code execution
eip stack group opener 2.3

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.8

Confidence

High

EPSS

0.012

Percentile

85.7%

An out-of-bounds write vulnerability exists in the Ethernet/IP server functionality of EIP Stack Group OpENer 2.3 and development commit 8c73bf3. A specially crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.

CNA Affected

[
  {
    "product": "EIP Stack Group",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "EIP Stack Group OpENer 2.3"
      },
      {
        "status": "affected",
        "version": "EIP Stack Group OpENer development commit 8c73bf3"
      }
    ]
  }
]

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.8

Confidence

High

EPSS

0.012

Percentile

85.7%

Related for CVELIST:CVE-2020-13556