IM
IronMonkey Threat Research

CVE-2020-14483 MEDIUM

Published: 2020-08-13 | Last Modified: 2024-11-21 | Status: Modified

Description

A timeout during a TLS handshake can result in the connection failing to terminate. This can result in a Niagara thread hanging and requires a manual restart of Niagara (Versions 4.6.96.28, 4.7.109.20, 4.7.110.32, 4.8.0.110) and Niagara Enterprise Security (Versions 2.4.31, 2.4.45, 4.8.0.35) to correct.

Additional Descriptions (1)

Un tiempo de espera durante un protocolo de enlace TLS puede resultar en que la conexión falle al terminar. Esto puede resultar en un bloqueo del hilo o subproceso de Niagara y requiere un reinicio manual de Niagara (versiones 4.6.96.28, 4.7.109.20, 4.7.110.32, 4.8.0.110) y Niagara Enterprise Security (versiones 2.4.31, 2.4.45, 4.8.0.35 ) parra corregir

CVSS Metrics

Base Score: 4.3 (MEDIUM)

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Attack VectorADJACENT_NETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactLOW

Source: [email protected]

Type: Primary

Exploitability Score: 2.8

Impact Score: 1.4

Base Score: 3.3 (LOW)

AV:A/AC:L/Au:N/C:N/I:N/A:P

Access VectorADJACENT_NETWORK
Access ComplexityLOW
AuthenticationNONE
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactPARTIAL

Source: [email protected]

Type: Primary

Exploitability Score: 6.5

Impact Score: 2.9

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-1088
[email protected] Primary
en NVD-CWE-Other

Affected Products

Vendor Product Version Update Type
tridium niagara 4.6.96.28 <built-in method update of dict object at 0x7c3c2ab0fd80> Application
tridium niagara 4.7.109.20 <built-in method update of dict object at 0x7c3c2ab0ce80> Application
tridium niagara 4.7.110.32 <built-in method update of dict object at 0x7c3c40d4f800> Application
tridium niagara 4.8.0.110 <built-in method update of dict object at 0x7c3c2ab0cd40> Application
tridium niagara_enterprise_security 2.4.31 <built-in method update of dict object at 0x7c3c2ab0de80> Application
tridium niagara_enterprise_security 2.4.45 <built-in method update of dict object at 0x7c3c2ab0fa80> Application
tridium niagara_enterprise_security 4.8.0.35 <built-in method update of dict object at 0x7c3c40d4f340> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:tridium:niagara:4.6.96.28:*:*:*:*:*:*:*
Yes cpe:2.3:a:tridium:niagara:4.7.109.20:*:*:*:*:*:*:*
Yes cpe:2.3:a:tridium:niagara:4.7.110.32:*:*:*:*:*:*:*
Yes cpe:2.3:a:tridium:niagara:4.8.0.110:*:*:*:*:*:*:*
Yes cpe:2.3:a:tridium:niagara_enterprise_security:2.4.31:*:*:*:*:*:*:*
Yes cpe:2.3:a:tridium:niagara_enterprise_security:2.4.45:*:*:*:*:*:*:*
Yes cpe:2.3:a:tridium:niagara_enterprise_security:4.8.0.35:*:*:*:*:*:*:*

References

Notification
Message here