Lucene search

K
cvelistTalosCVELIST:CVE-2020-6085
HistoryOct 19, 2020 - 8:46 p.m.

CVE-2020-6085

2020-10-1920:46:09
CWE-120
talos
www.cve.org
3
enip request path
allen-bradley flex io
dos vulnerability

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

29.8%

An exploitable denial of service vulnerability exists in the ENIP Request Path Logical Segment functionality of Allen-Bradley Flex IO 1794-AENT/B 4.003. A specially crafted network request can cause a loss of communications with the device resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability by sending an Electronic Key Segment with less than 0x18 bytes following the Key Format field.

CNA Affected

[
  {
    "product": "Allen Bradley",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Allen-Bradley Flex IO 1794-AENT/B 4.003"
      }
    ]
  }
]

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

29.8%

Related for CVELIST:CVE-2020-6085