Integer overflow in Siemens products - CVE-2020-13988

 

Integer overflow in Siemens products - CVE-2020-13988

Published: December 10, 2020


Vulnerability identifier: #VU48916
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-13988
CWE-ID: CWE-190
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to integer overflow. A remote attacker on the local network can send a specially crafted IP packet, trigger integer overflow and cause a denial of service on the target system.


Affected software

SENTRON PAC3200
SENTRON PAC4200
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
SIRIUS 3RW5 communication module Modbus TCP
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE CaaS Platform
SUSE Enterprise Storage
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Legacy Software
Ubuntu
open-iscsi (Ubuntu package)
iscsiuio
iscsiuio-debuginfo
libopeniscsiusr0_2_0
libopeniscsiusr0_2_0-debuginfo
open-iscsi
open-iscsi-debuginfo
open-iscsi-debugsource
open-iscsi-devel

How to mitigate CVE-2020-13988

Install updates from vendor's website.

SENTRON PAC3200 - update to 2.4.5
SENTRON PAC4200 - update to 2.0.1
open-iscsi (Ubuntu package) - addressed in versions Ubuntu Pro, 2.0.874-7.1ubuntu6.4
iscsiuio - addressed in versions 0.7.8.2-12.27.2, 0.7.8.2-13.42.1, 0.7.8.2-53.34.1
iscsiuio-debuginfo - addressed in versions 0.7.8.2-12.27.2, 0.7.8.2-13.42.1, 0.7.8.2-53.34.1
libopeniscsiusr0_2_0 - addressed in versions 2.0.876-12.27.2, 2.0.876-13.42.1, 2.0.876-53.34.1
libopeniscsiusr0_2_0-debuginfo - addressed in versions 2.0.876-12.27.2, 2.0.876-13.42.1, 2.0.876-53.34.1
open-iscsi - addressed in versions 2.0.876-12.27.2, 2.0.876-13.42.1, 2.0.876-53.34.1
open-iscsi-debuginfo - addressed in versions 2.0.876-12.27.2, 2.0.876-13.42.1, 2.0.876-53.34.1
open-iscsi-debugsource - addressed in versions 2.0.876-12.27.2, 2.0.876-13.42.1, 2.0.876-53.34.1
open-iscsi-devel - update to 2.0.876-13.42.1
Dell EMC Unity XT Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity VSA Operating Environment (OE) - update to 5.1.2.0.5.007

External References

Related Security Bulletins