CVE-2020-28400
high-risk
Published 2021-07-13
Affected devices contain a vulnerability that allows an unauthenticated attacker to trigger a denial of service condition. The vulnerability can be triggered if a large amount of DCP reset packets are sent to the device.
Do I need to act?
~
1.1% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10
High
NETWORK
/ LOW complexity
Affected Products (20)
Dk Standard Ethernet Controller Evaluation Kit Firmware
Ek-Ertec 200 Evaulation Kit Firmware
Ek-Ertec 200P Evaluation Kit Firmware
Ruggedcom Rm1224 Firmware
Scalance M-800 Firmware
Scalance W700 Firmware
Scalance W1700 Firmware
Scalance X200-4 P Irt Firmware
Scalance X201-3P Irt Firmware
Scalance X201-3P Irt Pro Firmware
Scalance X202-2 Irt Firmware
Scalance X202-2P Irt Pro Firmware
Scalance X204 Irt Firmware
Scalance X204 Irt Pro Firmware
Scalance X204-2 Firmware
Scalance X204-2Fm Firmware
Scalance X204-2Ld Firmware
Scalance X204-2Ld Ts Firmware
Scalance X204-2Ts Firmware
Affected Vendors
References (6)
Third Party Advisory
https://us-cert.cisa.gov/ics/advisories/icsa-21-194-03
Third Party Advisory
https://us-cert.cisa.gov/ics/advisories/icsa-21-194-03
57
/ 100
high-risk
Severity
26/34 · High
Exploitability
3/34 · Minimal
Exposure
28/34 · Critical