QID 591312

Date Published: 2023-02-03

QID 591312: Bosch Rexroth S20-PN-BK+/S20-ETH-BK Fieldbus Coupler Denial of Service (DoS) Vulnerability (BOSCH-SA-645125)

AFFECTED PRODUCTS
Rexroth S20-ETH-BK
Rexroth S20-PN-BK+

QID Detection Logic:
This QID checks for the Vulnerable version of Bosch Rexroth S20-PN-BK+/S20-ETH-BK Fieldbus Coupler using passive scanning.

An issue was discovered on PHOENIX CONTACT AXL F BK PN, AXL F BK ETH, and AXL F BK ETH XC devices. Incorrect handling of a request with non-standard symbols allows remote attackers to initiate a complete lock up of the bus coupler. Authentication of the request is not required.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution

    Customers are advised to refer to Bosch MITIGATIONS section bosch-sa-645125 for affected packages and patching details.

    CVEs related to QID 591312

    Software Advisories
    Advisory ID Software Component Link