CVE-2020-27736
Description
A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5.5), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.20), Nucleus NET (All versions), Nucleus ReadyStart V3 (All versions < V2017.02.3), Nucleus ReadyStart V4 (All versions < V4.1.0), Nucleus Source Code (Versions including affected DNS modules), SIMOTICS CONNECT 400 (All versions < V0.5.0.0), TALON TC Compact (BACnet) (All versions < V3.5.5), TALON TC Modular (BACnet) (All versions < V3.5.5). The DNS domain name label parsing functionality does not properly validate the null-terminated name in DNS-responses. The parsing of malformed responses could result in a read past the end of an allocated structure. An attacker with a privileged position in the network could leverage this vulnerability to cause a denial-of-service condition or leak the read memory.
Affected products
27<V3.5.5+ 1 more
- (no CPE)range: <V3.5.5
- (no CPE)range: All versions < V3.5.5
- Range: <V2017.02.3
<V4.1.0+ 1 more
- (no CPE)range: <V4.1.0
- cpe:2.3:a:siemens:nucleus_readystart_v4:*:*:*:*:*:*:*:*range: <4.1.0
Versions including affected DNS modules+ 2 more
- (no CPE)range: Versions including affected DNS modules
- (no CPE)range: Versions including affected DNS modules
- cpe:2.3:a:siemens:nucleus_source_code:-:*:*:*:*:*:*:*
<V0.5.0.0+ 1 more
- (no CPE)range: <V0.5.0.0
- (no CPE)range: All versions < V0.5.0.0
<V3.5.5+ 1 more
- (no CPE)range: <V3.5.5
- (no CPE)range: All versions < V3.5.5
<V2.8.20+ 1 more
- (no CPE)range: <V2.8.20
- (no CPE)range: All versions < V2.8.20
<V3.5.5+ 1 more
- (no CPE)range: <V3.5.5
- (no CPE)range: All versions < V3.5.5
<V2.8.20+ 1 more
- (no CPE)range: <V2.8.20
- (no CPE)range: All versions < V2.8.20
All versions+ 2 more
- (no CPE)range: All versions
- (no CPE)range: All versions
- cpe:2.3:a:siemens:nucleus_net:*:*:*:*:*:*:*:*
<V3.5.5+ 1 more
- (no CPE)range: <V3.5.5
- (no CPE)range: All versions < V3.5.5
All versions < V2017.02.3+ 1 more
- (no CPE)range: All versions < V2017.02.3
- (no CPE)range: All versions < V4.1.0
- cpe:2.3:a:siemens:nucleus_readystart_v3:*:*:*:*:*:*:*:*Range: <2017.02.3
- cpe:2.3:o:siemens:simotics_connect_400_firmware:*:*:*:*:*:*:*:*Range: <0.5.0.0
Patches
Vulnerability mechanics
References
3- cert-portal.siemens.com/productcert/pdf/ssa-669158.pdfnvdPatchVendor Advisory
- cert-portal.siemens.com/productcert/pdf/ssa-705111.pdfnvdPatchVendor Advisory
- cert-portal.siemens.com/productcert/pdf/ssa-180579.pdfnvd
News mentions
0No linked articles in our index yet.