// For flags

CVE-2020-25928

 

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The DNS feature in InterNiche NicheStack TCP/IP 4.0.1 is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component is: DNS response processing functions: dns_upcall(), getoffset(), dnc_set_answer(). The attack vector is: a specific DNS response packet. The code does not check the "response data length" field of individual DNS answers, which may cause out-of-bounds read/write operations, leading to Information leak, Denial-or-Service, or Remote Code Execution, depending on the context.

La funcionalidad DNS en InterNiche NicheStack TCP/IP versión 4.0.1 está afectada por: Desbordamiento del Búfer. El impacto es: ejecutar código arbitrario (remoto). El componente es: Funciones de procesamiento de respuestas DNS: dns_upcall(), getoffset(), dnc_set_answer(). El vector de ataque es: un paquete de respuesta DNS específico. El código no comprueba el campo "response data length" de las respuestas DNS individuales, lo que puede causar operaciones de lectura/escritura fuera de límites, conllevando a un filtrado de Información, Denegación de Servicio o Ejecución de Código Remota, dependiendo del contexto.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-09-24 CVE Reserved
  • 2021-08-18 CVE Published
  • 2024-08-04 CVE Updated
  • 2024-12-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-125: Out-of-bounds Read
  • CWE-787: Out-of-bounds Write
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Hcc-embedded
Search vendor "Hcc-embedded"
Nichestack Tcp\/ip
Search vendor "Hcc-embedded" for product "Nichestack Tcp\/ip"
4.0.1
Search vendor "Hcc-embedded" for product "Nichestack Tcp\/ip" and version "4.0.1"
-
Affected