Lucene search

K
nvd[email protected]NVD:CVE-2020-28393
HistoryMay 12, 2021 - 2:15 p.m.

CVE-2020-28393

2021-05-1214:15:11
CWE-682
web.nvd.nist.gov
8
denial-of-service
ospf
scalance xm-400
scalance xr-500
cve-2020-28393

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

61.4%

An unauthenticated remote attacker could create a permanent denial-of-service condition by sending specially crafted OSPF packets. Successful exploitation requires OSPF to be enabled on an affected device on the SCALANCE XM-400, XR-500 (All versions prior to v6.4).

Affected configurations

Nvd
Node
siemensscalance_xm-400_firmwareRange<6.4
AND
siemensscalance_xm-400Match-
Node
siemensscalance_xr524_firmwareRange<6.4
AND
siemensscalance_xr524Match-
Node
siemensscalance_xr526_firmwareRange<6.4
AND
siemensscalance_xr526Match-
Node
siemensscalance_xr528_firmwareRange<6.4
AND
siemensscalance_xr528Match-
Node
siemensscalance_xr552_firmwareRange<6.4
AND
siemensscalance_xr552Match-
Node
siemensscalance_xm416-4c_firmwareRange<6.4
AND
siemensscalance_xm416-4cMatch-
Node
siemensscalance_xm408-8c_firmwareRange<6.4
AND
siemensscalance_xm408-8cMatch-
Node
siemensscalance_xm408-4c_firmwareRange<6.4
AND
siemensscalance_xm408-4cMatch-
Node
siemensscalance_xm416-4c_l3_firmwareRange<6.4
AND
siemensscalance_xm416-4c_l3Match-
Node
siemensscalance_xm408-8c_l3_firmwareRange<6.4
AND
siemensscalance_xm408-8c_l3Match-
Node
siemensscalance_xm408-4c_l3_firmwareRange<6.4
AND
siemensscalance_xm408-4c_l3Match-
VendorProductVersionCPE
siemensscalance_xm-400_firmware*cpe:2.3:o:siemens:scalance_xm-400_firmware:*:*:*:*:*:*:*:*
siemensscalance_xm-400-cpe:2.3:h:siemens:scalance_xm-400:-:*:*:*:*:*:*:*
siemensscalance_xr524_firmware*cpe:2.3:o:siemens:scalance_xr524_firmware:*:*:*:*:*:*:*:*
siemensscalance_xr524-cpe:2.3:h:siemens:scalance_xr524:-:*:*:*:*:*:*:*
siemensscalance_xr526_firmware*cpe:2.3:o:siemens:scalance_xr526_firmware:*:*:*:*:*:*:*:*
siemensscalance_xr526-cpe:2.3:h:siemens:scalance_xr526:-:*:*:*:*:*:*:*
siemensscalance_xr528_firmware*cpe:2.3:o:siemens:scalance_xr528_firmware:*:*:*:*:*:*:*:*
siemensscalance_xr528-cpe:2.3:h:siemens:scalance_xr528:-:*:*:*:*:*:*:*
siemensscalance_xr552_firmware*cpe:2.3:o:siemens:scalance_xr552_firmware:*:*:*:*:*:*:*:*
siemensscalance_xr552-cpe:2.3:h:siemens:scalance_xr552:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 221

CVSS2

7.1

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:N/I:N/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.002

Percentile

61.4%

Related for NVD:CVE-2020-28393