Vulnerability Name:

CVE-2020-13987 (CCN-192752)

Assigned:2020-12-08
Published:2020-12-08
Updated:2022-08-06
Summary:An issue was discovered in Contiki through 3.0. An Out-of-Bounds Read vulnerability exists in the uIP TCP/IP Stack component when calculating the checksums for IP packets in upper_layer_chksum in net/ipv4/uip.c.
CVSS v3 Severity:7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
8.2 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H)
7.1 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): High
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
8.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): Complete
Vulnerability Type:CWE-125
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2020-13987

Source: CCN
Type: US-CERT VU#815128
Embedded TCP/IP stacks have memory corruption vulnerabilities

Source: CONFIRM
Type: Patch, Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-541018.pdf

Source: XF
Type: UNKNOWN
tcpipstacks-cve202013987-dos(192752)

Source: CCN
Type: uip GIT Repository
uIP

Source: CCN
Type: contiki GIT Repository
The Contiki Operating System

Source: CCN
Type: open-iscsi GIT Repository
open-iscsi

Source: CCN
Type: ICSA-20-343-01
Multiple Embedded TCP/IP Stacks

Source: MISC
Type: Third Party Advisory, US Government Resource
https://us-cert.cisa.gov/ics/advisories/icsa-20-343-01

Source: CCN
Type: Forescout Web site
AMNESIA:33

Source: MISC
Type: Third Party Advisory, US Government Resource
https://www.kb.cert.org/vuls/id/815128

Vulnerable Configuration:Configuration 1:
  • cpe:/a:uip_project:uip:*:*:*:*:*:*:*:* (Version <= 1.0)
  • AND
  • cpe:/o:contiki-os:contiki:*:*:*:*:*:*:*:* (Version <= 3.0)

  • Configuration 2:
  • cpe:/a:open-iscsi_project:open-iscsi:*:*:*:*:*:*:*:* (Version <= 2.1.12)

  • Configuration 3:
  • cpe:/o:siemens:sentron_3va_com100_firmware:*:*:*:*:*:*:*:* (Version < 4.4.1)
  • AND
  • cpe:/h:siemens:sentron_3va_com100:-:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:siemens:sentron_3va_com800_firmware:*:*:*:*:*:*:*:* (Version < 4.4.1)
  • AND
  • cpe:/h:siemens:sentron_3va_com800:-:*:*:*:*:*:*:*

  • Configuration 5:
  • cpe:/o:siemens:sentron_pac3200_firmware:*:*:*:*:*:*:*:* (Version < 2.4.7)
  • AND
  • cpe:/h:siemens:sentron_pac3200:-:*:*:*:*:*:*:*

  • Configuration 6:
  • cpe:/o:siemens:sentron_pac4200_firmware:*:*:*:*:*:*:*:* (Version < 2.3.0)
  • AND
  • cpe:/h:siemens:sentron_pac4200:-:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:7532
    P
    iscsiuio-0.7.8.6-150500.44.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:94584
    P
    iscsiuio-0.7.8.6-150400.37.6 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:2954
    P
    iscsiuio-0.7.8.6-150400.37.6 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:85
    P
    iscsiuio-0.7.8.6-30.1 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:102283
    P
    Security update for php7 (Important)
    2022-03-15
    oval:org.opensuse.security:def:99437
    P
    (Important)
    2021-12-06
    oval:org.opensuse.security:def:100861
    P
    iscsiuio-0.7.8.6-30.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62103
    P
    iscsiuio-0.7.8.6-30.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1014
    P
    iscsiuio-0.7.8.6-30.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:71844
    P
    iscsiuio-0.7.8.6-30.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:99636
    P
    (Moderate)
    2021-05-26
    oval:org.opensuse.security:def:99941
    P
    (Moderate)
    2021-05-05
    oval:org.opensuse.security:def:9687
    P
    Security update for open-iscsi (Important)
    2021-04-13
    oval:org.opensuse.security:def:6443
    P
    Security update for open-iscsi (Important)
    2021-04-13
    oval:org.opensuse.security:def:96839
    P
    Security update for open-iscsi (Important)
    2021-04-13
    oval:org.opensuse.security:def:92288
    P
    Security update for open-iscsi (Important)
    2021-04-13
    oval:org.opensuse.security:def:69444
    P
    Security update for open-iscsi (Important)
    2021-04-13
    oval:org.opensuse.security:def:8932
    P
    Security update for open-iscsi (Important)
    2021-04-13
    oval:org.opensuse.security:def:98848
    P
    Security update for open-iscsi (Important)
    2021-04-13
    oval:org.opensuse.security:def:93038
    P
    Security update for open-iscsi (Important)
    2021-04-13
    oval:org.opensuse.security:def:70378
    P
    Security update for open-iscsi (Important)
    2021-04-13
    oval:org.opensuse.security:def:10058
    P
    Security update for open-iscsi (Important)
    2021-04-13
    oval:org.opensuse.security:def:6468
    P
    Security update for open-iscsi (Important)
    2021-04-13
    oval:org.opensuse.security:def:108949
    P
    Security update for open-iscsi (Important)
    2021-04-13
    oval:org.opensuse.security:def:92487
    P
    Security update for open-iscsi (Important)
    2021-04-13
    oval:org.opensuse.security:def:69628
    P
    Security update for open-iscsi (Important)
    2021-04-13
    oval:org.opensuse.security:def:9304
    P
    Security update for open-iscsi (Important)
    2021-04-13
    oval:org.opensuse.security:def:99043
    P
    Security update for open-iscsi (Important)
    2021-04-13
    oval:org.opensuse.security:def:93191
    P
    Security update for open-iscsi (Important)
    2021-04-13
    oval:org.opensuse.security:def:91898
    P
    Security update for open-iscsi (Important)
    2021-04-13
    oval:org.opensuse.security:def:67532
    P
    Security update for open-iscsi (Important)
    2021-04-13
    oval:org.opensuse.security:def:10238
    P
    Security update for open-iscsi (Important)
    2021-04-13
    oval:org.opensuse.security:def:8559
    P
    Security update for open-iscsi (Important)
    2021-04-13
    oval:org.opensuse.security:def:92686
    P
    Security update for open-iscsi (Important)
    2021-04-13
    oval:org.opensuse.security:def:69827
    P
    Security update for open-iscsi (Important)
    2021-04-13
    oval:org.opensuse.security:def:9488
    P
    Security update for open-iscsi (Important)
    2021-04-13
    oval:org.opensuse.security:def:99238
    P
    Security update for open-iscsi (Important)
    2021-04-13
    oval:org.opensuse.security:def:95570
    P
    Security update for open-iscsi (Important)
    2021-04-13
    oval:org.opensuse.security:def:92093
    P
    Security update for open-iscsi (Important)
    2021-04-13
    oval:org.opensuse.security:def:67557
    P
    Security update for open-iscsi (Important)
    2021-04-13
    oval:org.opensuse.security:def:8737
    P
    Security update for open-iscsi (Important)
    2021-04-13
    oval:org.opensuse.security:def:92885
    P
    Security update for open-iscsi (Important)
    2021-04-13
    oval:org.opensuse.security:def:70198
    P
    Security update for open-iscsi (Important)
    2021-04-13
    oval:org.opensuse.security:def:60464
    P
    Security update for open-iscsi (Important)
    2021-03-01
    oval:org.opensuse.security:def:88252
    P
    Security update for open-iscsi (Important)
    2021-03-01
    oval:org.opensuse.security:def:127223
    P
    Security update for open-iscsi (Important)
    2021-03-01
    oval:org.opensuse.security:def:52013
    P
    Security update for open-iscsi (Important)
    2021-03-01
    oval:org.opensuse.security:def:34030
    P
    Security update for open-iscsi (Important)
    2021-03-01
    oval:org.opensuse.security:def:5963
    P
    Security update for open-iscsi (Important)
    2021-03-01
    oval:org.opensuse.security:def:88569
    P
    Security update for open-iscsi (Important)
    2021-03-01
    oval:org.opensuse.security:def:59595
    P
    Security update for open-iscsi (Important)
    2021-03-01
    oval:org.opensuse.security:def:34641
    P
    Security update for open-iscsi (Important)
    2021-03-01
    oval:org.opensuse.security:def:125658
    P
    Security update for open-iscsi (Important)
    2021-03-01
    oval:org.opensuse.security:def:89250
    P
    Security update for open-iscsi (Important)
    2021-03-01
    oval:org.opensuse.security:def:24025
    P
    Security update for open-iscsi (Important)
    2021-03-01
    oval:org.opensuse.security:def:59853
    P
    Security update for open-iscsi (Important)
    2021-03-01
    oval:org.opensuse.security:def:126826
    P
    Security update for open-iscsi (Important)
    2021-03-01
    oval:org.opensuse.security:def:89508
    P
    Security update for open-iscsi (Important)
    2021-03-01
    oval:org.opensuse.security:def:33772
    P
    Security update for open-iscsi (Important)
    2021-03-01
    BACK
    uip_project uip *
    contiki-os contiki *
    open-iscsi_project open-iscsi *
    siemens sentron 3va com100 firmware *
    siemens sentron 3va com100 -
    siemens sentron 3va com800 firmware *
    siemens sentron 3va com800 -
    siemens sentron pac3200 firmware *
    siemens sentron pac3200 -
    siemens sentron pac4200 firmware *
    siemens sentron pac4200 -