CERT-In Vulnerability Note
CIVN-2020-0438
Denial of Service Vulnerability in Cisco TalosEthernet/IP server
Original Issue Date:December 17, 2020
Severity Rating: MEDIUM
Software Affected
- OpENer: 2.3
- OpENer development commit 8c73bf3
Overview
A Vulnerability has been reported in the Ethernet/IP server functionality which could allow the remote attacker to perform a denial of service (DoS) attack.
Description
A Vulnerability exists in the Ethernet/IP server functionality of the EIP Stack Group OpENer 2.3 and development commit 8c73bf3due to insufficient validation of user-supplied input in the Ethernet/IP server functionality. An attacker could exploit this vulnerability by sending a specially crafted request to an affected device.
Successful exploitation of this vulnerability could allow the attacker to impact operations, leading to a denial of service (DoS) condition.
Solution
Apply appropriate updates as mentioned in:
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1143
Vendor Information
Cisco
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1143
References
Cisco
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1143
CVE Name
CVE-2020-13530
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|