IM
IronMonkey Threat Research

CVE-2020-6996 CRITICAL

Published: 2020-04-15 | Last Modified: 2024-11-21 | Status: Modified

Description

Triangle MicroWorks DNP3 Outstation LibrariesDNP3 Outstation .NET Protocol components and DNP3 Outstation ANSI C source code libraries are affected:3.16.00 through 3.25.01. A specially crafted message may cause a stack-based buffer overflow. Authentication is not required to exploit this vulnerability.

Additional Descriptions (1)

Librerías de Triangle MicroWorks DNP3 Outstation Los componentes del Protocolo .NET Outstation DNP3 y las bibliotecas de código fuente ANSI C de DNP3 Outstation se ven afectadas: 3.16.00 a 3.25.01. Un mensaje especialmente diseñado puede causar un desbordamiento del búfer basado en la pila. No se requiere autenticación para explotar esta vulnerabilidad.

CVSS Metrics

Base Score: 9.8 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 5.9

Base Score: 7.5 (HIGH)

AV:N/AC:L/Au:N/C:P/I:P/A:P

Access VectorNETWORK
Access ComplexityLOW
AuthenticationNONE
Confidentiality ImpactPARTIAL
Integrity ImpactPARTIAL
Availability ImpactPARTIAL

Source: [email protected]

Type: Primary

Exploitability Score: 10.0

Impact Score: 6.4

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-121
[email protected] Primary
en CWE-787

Affected Products

Vendor Product Version Update Type
trianglemicroworks dnp3_source_code_library * <built-in method update of dict object at 0x7e6108beb840> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:trianglemicroworks:dnp3_source_code_library:*:*:*:*:*:*:*:*

References

Notification
Message here