CVE-2020-28393
Summary
| CVE | CVE-2020-28393 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-12 14:15:00 UTC |
| Updated | 2021-05-21 14:03:00 UTC |
| Description | An unauthenticated remote attacker could create a permanent denial-of-service condition by sending specially crafted OSPF packets. Successful exploitation requires OSPF to be enabled on an affected device on the SCALANCE XM-400, XR-500 (All versions prior to v6.4). |
Risk And Classification
Problem Types: CWE-682
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Siemens | Scalance Xm-400 | - | All | All | All |
| Operating System | Siemens | Scalance Xm-400 Firmware | All | All | All | All |
| Hardware | Siemens | Scalance Xm408-4c | - | All | All | All |
| Operating System | Siemens | Scalance Xm408-4c Firmware | All | All | All | All |
| Hardware | Siemens | Scalance Xm408-4c L3 | - | All | All | All |
| Operating System | Siemens | Scalance Xm408-4c L3 Firmware | All | All | All | All |
| Hardware | Siemens | Scalance Xm408-8c | - | All | All | All |
| Operating System | Siemens | Scalance Xm408-8c Firmware | All | All | All | All |
| Hardware | Siemens | Scalance Xm408-8c L3 | - | All | All | All |
| Operating System | Siemens | Scalance Xm408-8c L3 Firmware | All | All | All | All |
| Hardware | Siemens | Scalance Xm416-4c | - | All | All | All |
| Operating System | Siemens | Scalance Xm416-4c Firmware | All | All | All | All |
| Hardware | Siemens | Scalance Xm416-4c L3 | - | All | All | All |
| Operating System | Siemens | Scalance Xm416-4c L3 Firmware | All | All | All | All |
| Hardware | Siemens | Scalance Xr524 | - | All | All | All |
| Operating System | Siemens | Scalance Xr524 Firmware | All | All | All | All |
| Hardware | Siemens | Scalance Xr526 | - | All | All | All |
| Operating System | Siemens | Scalance Xr526 Firmware | All | All | All | All |
| Hardware | Siemens | Scalance Xr528 | - | All | All | All |
| Operating System | Siemens | Scalance Xr528 Firmware | All | All | All | All |
| Hardware | Siemens | Scalance Xr552 | - | All | All | All |
| Operating System | Siemens | Scalance Xr552 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| cert-portal.siemens.com/productcert/pdf/ssa-116379.pdf | MISC | cert-portal.siemens.com | |
| Siemens SCALANCE XM-400 and XR-500 Devices | CISA | MISC | us-cert.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 590677 Siemens SCALANCE XM-400 and XR-500 Devices Vulnerability (ICSA-21-131-10)