VDB

SSA-541017

SSA-541017 PUBLISHED CVSS 6.5 MEDIUM

The TCP/IP stack (uIP) in affected devices is vulnerable to integer overflow when processing TCP Maximum Segment Size (MSS) options. (FSCT-2020-0008) An attacker located in the same network could trigger a Denial-of-Service condition on the device by sending a specially crafted IP packet.

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C

Affected Products

VendorProductVersions
SiemensSENTRON PAC3200T
SiemensSENTRON PAC2200 (without MID Approval)
SiemensSIRIUS 3RW5 communication module Modbus TCP
SiemensSENTRON PAC3200
SiemensSENTRON PAC4200
SiemensSENTRON 3VA COM100/800
SiemensSENTRON 3VA DSP800

Timeline

  • Dec 8, 2020 CVE Published
  • Apr 13, 2021 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›