CVE-2020-27736 Details
Description
A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5.5), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.20), Nucleus NET (All versions), Nucleus ReadyStart V3 (All versions < V2017.02.3), Nucleus ReadyStart V4 (All versions < V4.1.0), Nucleus Source Code (Versions including affected DNS modules), SIMOTICS CONNECT 400 (All versions < V0.5.0.0), TALON TC Compact (BACnet) (All versions < V3.5.5), TALON TC Modular (BACnet) (All versions < V3.5.5). The DNS domain name label parsing functionality does not properly validate the null-terminated name in DNS-responses. The parsing of malformed responses could result in a read past the end of an allocated structure. An attacker with a privileged position in the network could leverage this vulnerability to cause a denial-of-service condition or leak the read memory.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/pdf/ssa-180579.pdf | CVE | |
| https://cert-portal.siemens.com/productcert/pdf/ssa-669158.pdf | CVE | PatchVendor Advisory |
| https://cert-portal.siemens.com/productcert/pdf/ssa-705111.pdf | CVE | PatchVendor Advisory |
| https://cert-portal.siemens.com/productcert/pdf/ssa-180579.pdf | [email protected] | |
| https://cert-portal.siemens.com/productcert/pdf/ssa-669158.pdf | [email protected] | PatchVendor Advisory |
| https://cert-portal.siemens.com/productcert/pdf/ssa-705111.pdf | [email protected] | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
| CWE-170 | Improper Null Termination | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| siemens nucleus net | All versions |
CPE
Remediation
| |
| siemens nucleus readystart v3 | < 2017.02.3 |
CPE
Remediation
| |
| siemens nucleus readystart v4 | < 4.1.0 |
CPE
Remediation
| |
| siemens nucleus source code | All versions |
CPE
Remediation
| |
| siemens simotics connect 400 firmware | < 0.5.0.0 |
CPE
Remediation
| |
| siemens simotics connect 400 | All versions |
CPE
Remediation
| |
Change History
12 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Aug 8, 2023 | CVE Modified | [email protected] |
| Aug 5, 2022 | Reanalysis | [email protected] |
| Apr 29, 2022 | Modified Analysis | [email protected] |
| Jan 11, 2022 | CVE Modified | [email protected] |
| Nov 17, 2021 | CVE Modified | [email protected] |
| Nov 12, 2021 | Modified Analysis | [email protected] |
| Nov 10, 2021 | CVE Modified | [email protected] |
| Nov 9, 2021 | CVE Modified | [email protected] |
| Apr 30, 2021 | Initial Analysis | [email protected] |