// For flags

CVE-2020-25927

 

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The DNS feature in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Out-of-bounds Read. The impact is: a denial of service (remote). The component is: DNS response processing in function: dns_upcall(). The attack vector is: a specific DNS response packet. The code does not check whether the number of queries/responses specified in the DNS packet header corresponds to the query/response data available in the DNS packet.

La funcionalidad DNS en InterNiche NicheStack TCP/IP versión 4.0.1, está afectada por: Lectura fuera de límites. El impacto es: una denegación de servicio (remoto). El componente es: Procesamiento de respuestas DNS en la función: dns_upcall(). El vector de ataque es: un paquete de respuesta DNS específico. El código no comprueba si el número de consultas/respuestas especificado en el encabezado del paquete DNS se corresponde con los datos de consulta/respuesta disponibles en el paquete DNS.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-09-24 CVE Reserved
  • 2021-08-18 CVE Published
  • 2024-03-24 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-125: Out-of-bounds Read
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Hcc-embedded
Search vendor "Hcc-embedded"
Nichestack Tcp\/ip
Search vendor "Hcc-embedded" for product "Nichestack Tcp\/ip"
4.0.1
Search vendor "Hcc-embedded" for product "Nichestack Tcp\/ip" and version "4.0.1"
-
Affected