IM
IronMonkey Threat Research

CVE-2020-35684 HIGH

Published: 2021-08-19 | Last Modified: 2024-11-21 | Status: Modified

Description

An issue was discovered in HCC Nichestack 3.0. The code that parses TCP packets relies on an unchecked value of the IP payload size (extracted from the IP header) to compute the length of the TCP payload within the TCP checksum computation function. When the IP payload size is set to be smaller than the size of the IP header, the TCP checksum computation function may read out of bounds (a low-impact write-out-of-bounds is also possible).

Additional Descriptions (1)

Se ha detectado un problema en HCC Nichestack versión 3.0. El código que analiza los paquetes TCP se basa en un valor no comprobado del tamaño de la carga útil IP (extraído del encabezado IP) para calcular la longitud de la carga útil TCP dentro de la función de cálculo de la suma de comprobación TCP. Cuando el tamaño de la carga útil IP está configurado para ser menor que el tamaño del encabezado IP, la función de cálculo de la suma de comprobación TCP puede leer fuera de límites (también es posible una escritura fuera de límites de bajo impacto).

CVSS Metrics

Base Score: 7.5 (HIGH)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 3.6

Base Score: 5.0 (MEDIUM)

AV:N/AC:L/Au:N/C:N/I:N/A:P

Access VectorNETWORK
Access ComplexityLOW
AuthenticationNONE
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactPARTIAL

Source: [email protected]

Type: Primary

Exploitability Score: 10.0

Impact Score: 2.9

Weaknesses

Source Type Description
[email protected] Primary
en CWE-20

Affected Products

Vendor Product Version Update Type
hcc-embedded nichestack 3.0 <built-in method update of dict object at 0x7e60ba04fb80> Application
siemens sentron_3wl_com35_firmware * <built-in method update of dict object at 0x7e60bbef5540> Operating System
siemens sentron_3wa_com190_firmware * <built-in method update of dict object at 0x7e60bbef7040> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:hcc-embedded:nichestack:3.0:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:sentron_3wl_com35_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:sentron_3wl_com35:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:siemens:sentron_3wa_com190_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:siemens:sentron_3wa_com190:-:*:*:*:*:*:*:*

References

Notification
Message here