CVE-2020-27827
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.
Affected (27)
Products: Lldpd Project: Lldpd · Openvswitch: Openvswitch · Redhat: Enterprise Linux, Openshift Container Platform, Openstack, Virtualization · +2 more
Show all products
Lldpd Project: Lldpd · Openvswitch: Openvswitch · Redhat: Enterprise Linux, Openshift Container Platform, Openstack, Virtualization · Fedoraproject: Fedora · Siemens: Simatic Hmi Unified Comfort Panels Firmware, Simatic Net Cp 1243 1 Firmware, Simatic Net Cp 1243 8 Irc Firmware, Simatic Net Cp 1542sp 1 Firmware, Simatic Net Cp 1542sp 1 Irc Firmware, Simatic Net Cp 1543 1 Firmware, Simatic Net Cp 1543sp 1 Firmware, Simatic Net Cp 1545 1 Firmware, Tim 1531 Irc Firmware, Sinumerik One Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.0.8 | |
| From 2.10.0 to 2.10.6 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.0 | |
| Version 4.0 | |
| Version 10 | |
| Version 4.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 33 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 17 |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Hmi Unified Comfort Panels | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Net Cp 1243 1 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Net Cp 1243 8 Irc | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Net Cp 1542sp 1 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Net Cp 1542sp 1 Irc | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Net Cp 1543 1 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Net Cp 1543sp 1 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Siemens Simatic Net Cp 1545 1 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.2 |
| Running on/with | Platform Versions |
|---|---|
Siemens Tim 1531 Irc | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.0.1 |
| Running on/with | Platform Versions |
|---|---|
Siemens Sinumerik One | All versions |
References (16)
Source: secalert@redhat.com
Issue TrackingMitigationPatchThird Party Advisory
Source: secalert@redhat.com
PatchThird Party Advisory
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Mailing ListMitigationVendor Advisory
Source: secalert@redhat.com
Source: secalert@redhat.com
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMitigationPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListMitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.