In Hilscher rcX RTOS versions prios to V2.1.14.1 the actual UDP packet length is not verified against the length indicated by the packet. This may lead to a denial of service of the affected device.
References
| Link | Resource |
|---|---|
| https://cert.vde.com/de-de/advisories/vde-2021-018 | Third Party Advisory |
| https://kb.hilscher.com/display/ISMS/2019-04-10+Wrong+handling+of+the+UDP+checksum | Vendor Advisory |
| https://cert.vde.com/de-de/advisories/vde-2021-018 | Third Party Advisory |
| https://kb.hilscher.com/display/ISMS/2019-04-10+Wrong+handling+of+the+UDP+checksum | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
| AND |
|
Configuration 6 (hide)
| AND |
|
Configuration 7 (hide)
| AND |
|
Configuration 8 (hide)
| AND |
|
Configuration 9 (hide)
| AND |
|
History
21 Nov 2024, 05:47
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://cert.vde.com/de-de/advisories/vde-2021-018 - Third Party Advisory | |
| References | () https://kb.hilscher.com/display/ISMS/2019-04-10+Wrong+handling+of+the+UDP+checksum - Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : 5.0
v3 : 8.6 |
09 Sep 2021, 12:51
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:pepperi-fuchs:ice1-16dio-g60l-v1d_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:pepperi-fuchs:ice1-16dio-g60l-c1-v1d:-:*:*:*:*:*:*:* cpe:2.3:h:pepperi-fuchs:ice1-16di-g60l-v1d:-:*:*:*:*:*:*:* cpe:2.3:h:pepperi-fuchs:ice1-8di8do-g60l-c1-v1d:-:*:*:*:*:*:*:* cpe:2.3:o:pepperi-fuchs:ice1-8di8do-g60l-v1d_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:pepperi-fuchs:ice1-8iol-g60l-v1d_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:pepperi-fuchs:ice1-8di8do-g60l-v1d:-:*:*:*:*:*:*:* cpe:2.3:h:pepperi-fuchs:ice1-8iol-s2-g60l-v1d:-:*:*:*:*:*:*:* cpe:2.3:h:pepperi-fuchs:ice1-16dio-g60l-v1d:-:*:*:*:*:*:*:* cpe:2.3:o:pepperi-fuchs:ice1-8iol-g30l-v1d_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:pepperi-fuchs:ice1-8iol-s2-g60l-v1d_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:pepperi-fuchs:ice1-8di8do-g60l-c1-v1d_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:pepperi-fuchs:ice1-8iol-g30l-v1d:-:*:*:*:*:*:*:* cpe:2.3:h:pepperi-fuchs:ice1-8iol-g60l-v1d:-:*:*:*:*:*:*:* cpe:2.3:o:pepperi-fuchs:ice1-16di-g60l-v1d_firmware:*:*:*:*:*:*:*:* |
cpe:2.3:h:pepperl-fuchs:ice1-8di8do-g60l-v1d:-:*:*:*:*:*:*:* cpe:2.3:h:pepperl-fuchs:ice1-8iol-g30l-v1d:-:*:*:*:*:*:*:* cpe:2.3:o:pepperl-fuchs:ice1-16di-g60l-v1d_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:pepperl-fuchs:ice1-16dio-g60l-v1d:-:*:*:*:*:*:*:* cpe:2.3:o:pepperl-fuchs:ice1-8di8do-g60l-c1-v1d_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:pepperl-fuchs:ice1-8iol-s2-g60l-v1d_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:pepperl-fuchs:ice1-16di-g60l-v1d:-:*:*:*:*:*:*:* cpe:2.3:o:pepperl-fuchs:ice1-8iol-g60l-v1d_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:pepperl-fuchs:ice1-16dio-g60l-c1-v1d_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:pepperl-fuchs:ice1-16dio-g60l-c1-v1d:-:*:*:*:*:*:*:* cpe:2.3:o:pepperl-fuchs:ice1-8iol-g30l-v1d_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:pepperl-fuchs:ice1-8iol-s2-g60l-v1d:-:*:*:*:*:*:*:* cpe:2.3:o:pepperl-fuchs:ice1-16dio-g60l-v1d_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:pepperl-fuchs:ice1-8iol-g60l-v1d:-:*:*:*:*:*:*:* cpe:2.3:h:pepperl-fuchs:ice1-8di8do-g60l-c1-v1d:-:*:*:*:*:*:*:* cpe:2.3:o:pepperl-fuchs:ice1-8di8do-g60l-v1d_firmware:*:*:*:*:*:*:*:* |
21 May 2021, 19:37
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-119 | |
| CVSS |
v2 : v3 : |
v2 : 5.0
v3 : 7.5 |
| References | (CONFIRM) https://kb.hilscher.com/display/ISMS/2019-04-10+Wrong+handling+of+the+UDP+checksum - Vendor Advisory | |
| References | (CONFIRM) https://cert.vde.com/de-de/advisories/vde-2021-018 - Third Party Advisory | |
| CPE | cpe:2.3:o:pepperi-fuchs:ice1-16dio-g60l-c1-v1d_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:pepperi-fuchs:ice1-8iol-g30l-v1d:-:*:*:*:*:*:*:* cpe:2.3:h:pepperi-fuchs:ice1-8di8do-g60l-v1d:-:*:*:*:*:*:*:* cpe:2.3:h:pepperi-fuchs:ice1-8di8do-g60l-c1-v1d:-:*:*:*:*:*:*:* cpe:2.3:h:pepperi-fuchs:ice1-16di-g60l-v1d:-:*:*:*:*:*:*:* cpe:2.3:h:pepperi-fuchs:ice1-8iol-s2-g60l-v1d:-:*:*:*:*:*:*:* cpe:2.3:o:pepperi-fuchs:ice1-8iol-g60l-v1d_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:pepperi-fuchs:ice1-8di8do-g60l-c1-v1d_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:pepperi-fuchs:ice1-16di-g60l-v1d_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:pepperi-fuchs:ice1-16dio-g60l-v1d_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:pepperi-fuchs:ice1-8iol-g60l-v1d:-:*:*:*:*:*:*:* cpe:2.3:o:pepperi-fuchs:ice1-8di8do-g60l-v1d_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:pepperi-fuchs:ice1-16dio-g60l-c1-v1d:-:*:*:*:*:*:*:* cpe:2.3:h:pepperi-fuchs:ice1-16dio-g60l-v1d:-:*:*:*:*:*:*:* cpe:2.3:a:hilscher:rcx_rtos:*:*:*:*:*:*:*:* cpe:2.3:o:pepperi-fuchs:ice1-8iol-g30l-v1d_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:pepperi-fuchs:ice1-8iol-s2-g60l-v1d_firmware:*:*:*:*:*:*:*:* |
Information
Published : 2021-05-13 14:15
Updated : 2024-11-21 05:47
NVD link : CVE-2021-20988
Mitre link : CVE-2021-20988
CVE.ORG link : CVE-2021-20988
JSON object : View
Products Affected
pepperl-fuchs
- ice1-16di-g60l-v1d_firmware
- ice1-8di8do-g60l-v1d_firmware
- ice1-16dio-g60l-v1d
- ice1-8iol-s2-g60l-v1d_firmware
- ice1-8di8do-g60l-v1d
- ice1-16dio-g60l-c1-v1d_firmware
- ice1-8di8do-g60l-c1-v1d_firmware
- ice1-16dio-g60l-v1d_firmware
- ice1-8iol-g30l-v1d
- ice1-8iol-s2-g60l-v1d
- ice1-8iol-g60l-v1d
- ice1-8di8do-g60l-c1-v1d
- ice1-8iol-g60l-v1d_firmware
- ice1-16dio-g60l-c1-v1d
- ice1-16di-g60l-v1d
- ice1-8iol-g30l-v1d_firmware
hilscher
- rcx_rtos
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
