VYPR
Unrated severityNVD Advisory· Published Nov 12, 2020· Updated Aug 4, 2024

CVE-2020-24573

CVE-2020-24573

Description

BAB TECHNOLOGIE GmbH eibPort V3 prior to 3.8.3 devices allow denial of service (Uncontrolled Resource Consumption) via requests to the lighttpd component.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

BAB TECHNOLOGIE eibPort V3 before 3.8.3 allows unauthenticated remote attackers to cause denial of service via a malformed HTTP request to lighttpd.

Vulnerability

The eibPort V3 devices running firmware version 3.8.2 and earlier use lighttpd version 1.4.31, which is vulnerable to CWE-400 Uncontrolled Resource Consumption [1]. Sending a crafted HTTP request with a malformed Connection header (e.g., Connection: TC,,Keep-Alive) triggers high CPU usage, rendering the device unresponsive.

Exploitation

An unauthenticated attacker with network access to the web interface can exploit this by sending a single malformed HTTP GET request with a crafted Connection header [1]. The request causes lighttpd to enter a high CPU loop (99% usage), and a simple restart of the lighttpd process may not suffice; a full reboot is required to recover.

Impact

Successful exploitation results in a denial of service condition where the eibPort becomes unresponsive, impacting all services including building automation control. This is a network-based attack with no authentication required, and the impact is high availability loss, with no effect on confidentiality or integrity.

Mitigation

The vendor released firmware version 3.8.3 in November 2020, which updates lighttpd to version 1.4.55, fixing the vulnerability [1]. Users should upgrade to version 3.8.3 or later. No workaround is mentioned in the reference.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.