CVE-2020-27827

A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:lldpd_project:lldpd:*:*:*:*:*:*:*:*
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:10:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:13:*:*:*:*:*:*:*
cpe:2.3:a:redhat:virtualization:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:h:siemens:simatic_hmi_unified_comfort_panels:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_hmi_unified_comfort_panels_firmware:*:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:h:siemens:simatic_net_cp_1243-1:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_net_cp_1243-1_firmware:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:h:siemens:simatic_net_cp_1243-8_irc:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_net_cp_1243-8_irc_firmware:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:h:siemens:simatic_net_cp_1542sp-1:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_net_cp_1542sp-1_firmware:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:h:siemens:simatic_net_cp_1542sp-1_irc:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_net_cp_1542sp-1_irc_firmware:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:h:siemens:simatic_net_cp_1543-1:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_net_cp_1543-1_firmware:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:h:siemens:simatic_net_cp_1543sp-1:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_net_cp_1543sp-1_firmware:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:siemens:simatic_net_cp_1545-1_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_net_cp_1545-1:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:siemens:tim_1531_irc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:tim_1531_irc:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:siemens:sinumerik_one_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:sinumerik_one:-:*:*:*:*:*:*:*

History

26 Nov 2023, 11:15

Type Values Removed Values Added
CWE CWE-400
References
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3T5XHPOGIPWCRRPJUE6P3HVC5PTSD5JS/', 'name': 'FEDORA-2023-c0c184a019', 'tags': [], 'refsource': 'FEDORA'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JYA4AMJXCNF6UPFG36L2TPPT32C242SP/', 'name': 'FEDORA-2023-88991d2713', 'tags': [], 'refsource': 'FEDORA'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SKQWHG2SZJZSGC7PXVDAEJYBN7ESDR7D/', 'name': 'FEDORA-2023-3e4feeadec', 'tags': [], 'refsource': 'FEDORA'}
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JYA4AMJXCNF6UPFG36L2TPPT32C242SP/ -
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SKQWHG2SZJZSGC7PXVDAEJYBN7ESDR7D/ -
  • () https://security.gentoo.org/glsa/202311-16 -
  • () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3T5XHPOGIPWCRRPJUE6P3HVC5PTSD5JS/ -

20 Apr 2023, 07:15

Type Values Removed Values Added
CWE CWE-400
References
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3T5XHPOGIPWCRRPJUE6P3HVC5PTSD5JS/ -
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JYA4AMJXCNF6UPFG36L2TPPT32C242SP/ -
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SKQWHG2SZJZSGC7PXVDAEJYBN7ESDR7D/ -
References (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-941426.pdf - (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-941426.pdf - Patch, Third Party Advisory
References (MISC) https://us-cert.cisa.gov/ics/advisories/icsa-21-194-07 - (MISC) https://us-cert.cisa.gov/ics/advisories/icsa-21-194-07 - Third Party Advisory, US Government Resource
CPE cpe:2.3:o:siemens:simatic_net_cp_1243-8_irc_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:sinumerik_one_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_net_cp_1243-1_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_net_cp_1543sp-1:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_net_cp_1545-1:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:sinumerik_one:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_net_cp_1542sp-1:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_net_cp_1542sp-1_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_net_cp_1542sp-1_irc_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_net_cp_1543-1:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_net_cp_1243-8_irc:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_net_cp_1542sp-1_irc:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_net_cp_1543-1_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_net_cp_1543sp-1_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_hmi_unified_comfort_panels_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:tim_1531_irc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_net_cp_1545-1_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:tim_1531_irc:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_hmi_unified_comfort_panels:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_net_cp_1243-1:-:*:*:*:*:*:*:*

04 Aug 2021, 17:14

Type Values Removed Values Added
References
  • (MISC) https://us-cert.cisa.gov/ics/advisories/icsa-21-194-07 -
CPE cpe:2.3:a:redhat:openstack:13.0:*:*:*:*:*:*:* cpe:2.3:a:redhat:openstack:13:*:*:*:*:*:*:*

02 Aug 2021, 17:15

Type Values Removed Values Added
References
  • (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-941426.pdf -

Information

Published : 2021-03-18 17:15

Updated : 2024-02-04 21:23


NVD link : CVE-2020-27827

Mitre link : CVE-2020-27827

CVE.ORG link : CVE-2020-27827


JSON object : View

Products Affected

siemens

  • simatic_net_cp_1543-1_firmware
  • simatic_net_cp_1542sp-1_firmware
  • simatic_net_cp_1543sp-1
  • simatic_net_cp_1545-1_firmware
  • simatic_net_cp_1243-8_irc
  • tim_1531_irc
  • simatic_net_cp_1542sp-1_irc
  • simatic_hmi_unified_comfort_panels
  • simatic_net_cp_1243-8_irc_firmware
  • simatic_net_cp_1543sp-1_firmware
  • simatic_net_cp_1545-1
  • tim_1531_irc_firmware
  • sinumerik_one_firmware
  • simatic_net_cp_1542sp-1_irc_firmware
  • simatic_net_cp_1243-1
  • sinumerik_one
  • simatic_net_cp_1542sp-1
  • simatic_net_cp_1543-1
  • simatic_net_cp_1243-1_firmware
  • simatic_hmi_unified_comfort_panels_firmware

redhat

  • enterprise_linux
  • virtualization
  • openshift_container_platform
  • openstack

fedoraproject

  • fedora

lldpd_project

  • lldpd

openvswitch

  • openvswitch
CWE
CWE-400

Uncontrolled Resource Consumption