CVE-2020-17437
An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. When the Urgent flag is set in a TCP packet, and the stack is configured to ignore the urgent data, the stack attempts to use the value of the Urgent pointer bytes to separate the Urgent data from the normal data, by calculating the offset at which the normal data should be present in the global buffer. However, the length of this offset is not checked; therefore, for large values of the Urgent pointer bytes, the data pointer can point to memory that is way beyond the data buffer in uip_process in uip.c.
Published:Dec 9, 2020
Last Modified:Nov 21, 2024
EPS:Dec 11, 2020
EPSS Score:0.00242
CVSS Score:8.2
Affected Products
Vendor
Product
Action
Vendor
Contiki-os
Product
Contiki
Contiki-os
Contiki
Vendor
Open-iscsi Project
Product
Open-iscsi
Open-iscsi Project
Open-iscsi
Vendor
Siemens
Product
Sentron 3va Com100
Siemens
Sentron 3va Com100
Vendor
Siemens
Product
Sentron 3va Com100 Firmware
Siemens
Sentron 3va Com100 Firmware
Vendor
Siemens
Product
Sentron 3va Com800
Siemens
Sentron 3va Com800
Vendor
Siemens
Product
Sentron 3va Com800 Firmware
Siemens
Sentron 3va Com800 Firmware
Vendor
Siemens
Product
Sentron 3va Dsp800
Siemens
Sentron 3va Dsp800
Vendor
Siemens
Product
Sentron 3va Dsp800 Firmware
Siemens
Sentron 3va Dsp800 Firmware
Vendor
Siemens
Product
Sentron Pac2200
Siemens
Sentron Pac2200
Vendor
Siemens
Product
Sentron Pac2200 Clp
Siemens
Sentron Pac2200 Clp
Vendor
Siemens
Product
Sentron Pac2200 Clp Firmware
Siemens
Sentron Pac2200 Clp Firmware
Vendor
Siemens
Product
Sentron Pac2200 Firmware
Siemens
Sentron Pac2200 Firmware
Vendor
Siemens
Product
Sentron Pac3200
Siemens
Sentron Pac3200
Vendor
Siemens
Product
Sentron Pac3200 Firmware
Siemens
Sentron Pac3200 Firmware
Vendor
Siemens
Product
Sentron Pac3200t
Siemens
Sentron Pac3200t
Vendor
Siemens
Product
Sentron Pac3200t Firmware
Siemens
Sentron Pac3200t Firmware
Vendor
Siemens
Product
Sentron Pac3220
Siemens
Sentron Pac3220
Vendor
Siemens
Product
Sentron Pac3220 Firmware
Siemens
Sentron Pac3220 Firmware
Vendor
Siemens
Product
Sentron Pac4200
Siemens
Sentron Pac4200
Vendor
Siemens
Product
Sentron Pac4200 Firmware
Siemens
Sentron Pac4200 Firmware
Vendor
Uip Project
Product
Uip
Uip Project
Uip
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
