CVE-2020-6086
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An exploitable denial of service vulnerability exists in the ENIP Request Path Data Segment functionality of Allen-Bradley Flex IO 1794-AENT/B. A specially crafted network request can cause a loss of communications with the device resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability.If the Simple Segment Sub-Type is supplied, the device treats the byte following as the Data Size in words. When this value represents a size greater than what remains in the packet data, the device enters a fault state where communication with the device is lost and a physical power cycle is required.
Se presenta una vulnerabilidad de denegación de servicio explotable en la funcionalidad ENIP Request Path Data Segment de Allen-Bradley Flex IO 1794-AENT/B. Una petición de red especialmente diseñada puede causar una pérdida de comunicaciones con el dispositivo resultando en una denegación de servicio. Un atacante puede enviar un paquete malicioso para activar esta vulnerabilidad. Si el Simple Segment Sub-Type es suministrado, el dispositivo trata el byte siguiente como el Data Size en palabras. Cuando este valor representa un tamaño mayor que el que queda en el paquete de datos, el dispositivo entra en un estado de falla en el que se pierde la comunicación con el dispositivo y un ciclo de energía físico es requerido
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-01-07 CVE Reserved
- 2020-10-14 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- 2024-10-21 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1007 | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Rockwellautomation Search vendor "Rockwellautomation" | Flex I\/o 1794-aent\/b Firmware Search vendor "Rockwellautomation" for product "Flex I\/o 1794-aent\/b Firmware" | 4.003 Search vendor "Rockwellautomation" for product "Flex I\/o 1794-aent\/b Firmware" and version "4.003" | - |
Affected
| in | Rockwellautomation Search vendor "Rockwellautomation" | Flex I\/o 1794-aent\/b Search vendor "Rockwellautomation" for product "Flex I\/o 1794-aent\/b" | - | - |
Safe
|