Denial of Service Vulnerability in Allen-Bradley Flex IO 1794-AENT/B
CVE-2020-6086

7.5HIGH

Key Information:

Vendor
CVE Published:
14 October 2020

What is CVE-2020-6086?

A vulnerability in the ENIP Request Path Data Segment functionality of the Allen-Bradley Flex IO 1794-AENT/B can be exploited to cause a denial of service. By sending a specifically crafted network request, an attacker can trigger the device to enter a fault state, resulting in a loss of communication. If the Simple Segment Sub-Type is incorrectly specified, the device misinterprets the ensuing byte as the Data Size, which can lead to an error when the provided size exceeds the available packet data. This condition necessitates a physical power cycle to restore functionality.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Allen Bradley Allen-Bradley Flex IO 1794-AENT/B 4.003

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.