CVE Feed

    Dashboard / CVE / CVE-2020-28393

    CVE-2020-28393

    An unauthenticated remote attacker could create a permanent denial-of-service condition by sending specially crafted OSPF packets. Successful exploitation requires OSPF to be enabled on an affected device on the SCALANCE XM-400, XR-500 (All versions prior to v6.4).

    Published:May 12, 2021
    Last Modified:Nov 21, 2024
    EPS:May 12, 2021
    EPSS Score:0.00528
    CVSS Score:7.5

    Affected Products

    Vendor
    Siemens
    Product
    Scalance Xm-400
    Vendor
    Siemens
    Product
    Scalance Xm-400 Firmware
    Vendor
    Siemens
    Product
    Scalance Xm408-4c
    Vendor
    Siemens
    Product
    Scalance Xm408-4c Firmware
    Vendor
    Siemens
    Product
    Scalance Xm408-4c L3
    Vendor
    Siemens
    Product
    Scalance Xm408-4c L3 Firmware
    Vendor
    Siemens
    Product
    Scalance Xm408-8c
    Vendor
    Siemens
    Product
    Scalance Xm408-8c Firmware
    Vendor
    Siemens
    Product
    Scalance Xm408-8c L3
    Vendor
    Siemens
    Product
    Scalance Xm408-8c L3 Firmware
    Vendor
    Siemens
    Product
    Scalance Xm416-4c
    Vendor
    Siemens
    Product
    Scalance Xm416-4c Firmware
    Vendor
    Siemens
    Product
    Scalance Xm416-4c L3
    Vendor
    Siemens
    Product
    Scalance Xm416-4c L3 Firmware
    Vendor
    Siemens
    Product
    Scalance Xr524
    Vendor
    Siemens
    Product
    Scalance Xr524 Firmware
    Vendor
    Siemens
    Product
    Scalance Xr526
    Vendor
    Siemens
    Product
    Scalance Xr526 Firmware
    Vendor
    Siemens
    Product
    Scalance Xr528
    Vendor
    Siemens
    Product
    Scalance Xr528 Firmware
    Vendor
    Siemens
    Product
    Scalance Xr552
    Vendor
    Siemens
    Product
    Scalance Xr552 Firmware

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High