CVE-2020-13987

An issue was discovered in Contiki through 3.0. An Out-of-Bounds Read vulnerability exists in the uIP TCP/IP Stack component when calculating the checksums for IP packets in upper_layer_chksum in net/ipv4/uip.c.
References
Link Resource
https://cert-portal.siemens.com/productcert/pdf/ssa-541018.pdf Patch Third Party Advisory
https://us-cert.cisa.gov/ics/advisories/icsa-20-343-01 Third Party Advisory US Government Resource
https://www.kb.cert.org/vuls/id/815128 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:uip_project:uip:*:*:*:*:*:*:*:*
cpe:2.3:o:contiki-os:contiki:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:open-iscsi_project:open-iscsi:*:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:siemens:sentron_3va_com100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:sentron_3va_com100:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:siemens:sentron_3va_com800_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:sentron_3va_com800:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:siemens:sentron_pac3200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:sentron_pac3200:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:siemens:sentron_pac4200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:sentron_pac4200:-:*:*:*:*:*:*:*

History

06 Aug 2022, 03:52

Type Values Removed Values Added
CPE cpe:2.3:a:uip_project:uip:*:*:*:*:*:*:*:*
cpe:2.3:a:open-iscsi_project:open-iscsi:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:sentron_3va_com100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:sentron_pac3200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:sentron_pac3200:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:sentron_3va_com800_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:sentron_3va_com100:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:sentron_pac4200:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:sentron_3va_com800:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:sentron_pac4200_firmware:*:*:*:*:*:*:*:*
References (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-541018.pdf - (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-541018.pdf - Patch, Third Party Advisory

Information

Published : 2020-12-11 22:15

Updated : 2024-02-04 21:23


NVD link : CVE-2020-13987

Mitre link : CVE-2020-13987

CVE.ORG link : CVE-2020-13987


JSON object : View

Products Affected

contiki-os

  • contiki

siemens

  • sentron_3va_com100_firmware
  • sentron_pac4200
  • sentron_3va_com800_firmware
  • sentron_3va_com800
  • sentron_3va_com100
  • sentron_pac3200_firmware
  • sentron_pac4200_firmware
  • sentron_pac3200

uip_project

  • uip

open-iscsi_project

  • open-iscsi
CWE
CWE-125

Out-of-bounds Read