Denial of Service Vulnerability in Siemens Industrial Devices
CVE-2020-28400

8.7HIGH

What is CVE-2020-28400?

Siemens Industrial Devices are susceptible to a vulnerability that enables unauthenticated attackers to induce a denial of service. By sending a large volume of DCP reset packets to the device, attackers can disrupt device operations, leading to potential outages and service degradation. This poses significant risks for systems relying on these devices, affecting both functionality and availability.

Affected Version(s)

Development/Evaluation Kits for PROFINET IO: DK Standard Ethernet Controller 0

Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200 0

Development/Evaluation Kits for PROFINET IO: EK-ERTEC 200P 0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.