CVE-2020-27737 Details
Description
A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5.5), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.20), Nucleus NET (All versions), Nucleus ReadyStart V3 (All versions < V2017.02.3), Nucleus ReadyStart V4 (All versions < V4.1.0), Nucleus Source Code (Versions including affected DNS modules), SIMOTICS CONNECT 400 (All versions < V0.5.0.0), TALON TC Compact (BACnet) (All versions < V3.5.5), TALON TC Modular (BACnet) (All versions < V3.5.5). The DNS response parsing functionality does not properly validate various length and counts of the records. The parsing of malformed responses could result in a read past the end of an allocated structure. An attacker with a privileged position in the network could leverage this vulnerability to cause a denial-of-service condition or leak the memory past the allocated structure.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/pdf/ssa-180579.pdf | CVE | |
| https://cert-portal.siemens.com/productcert/pdf/ssa-669158.pdf | CVE | PatchVendor Advisory |
| https://cert-portal.siemens.com/productcert/pdf/ssa-705111.pdf | CVE | PatchVendor Advisory |
| https://cert-portal.siemens.com/productcert/pdf/ssa-180579.pdf | [email protected] | |
| https://cert-portal.siemens.com/productcert/pdf/ssa-669158.pdf | [email protected] | PatchVendor Advisory |
| https://cert-portal.siemens.com/productcert/pdf/ssa-705111.pdf | [email protected] | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| siemens simotics connect 400 firmware | < 0.5.0.0 |
CPE
Remediation
| |
| siemens simotics connect 400 | All versions |
CPE
Remediation
| |
| siemens nucleus net | All versions |
CPE
Remediation
| |
| siemens nucleus readystart v3 | < 2017.02.3 |
CPE
Remediation
| |
| siemens nucleus readystart v4 | < 4.1.0 |
CPE
Remediation
| |
| siemens nucleus source code | All versions |
CPE
Remediation
| |
Change History
13 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Aug 8, 2023 | CVE Modified | [email protected] |
| Apr 29, 2022 | Modified Analysis | [email protected] |
| Mar 10, 2022 | CVE Modified | [email protected] |
| Mar 8, 2022 | CVE Modified | [email protected] |
| Jan 11, 2022 | CVE Modified | [email protected] |
| Nov 17, 2021 | CVE Modified | [email protected] |
| Nov 12, 2021 | Modified Analysis | [email protected] |
| Nov 10, 2021 | CVE Modified | [email protected] |
| Nov 9, 2021 | CVE Modified | [email protected] |
| Apr 30, 2021 | Initial Analysis | [email protected] |