CVE-2020-37216

Severity CVSS v4.0:
HIGH
Type:
CWE-20 Input Validation
Publication date:
03/04/2026
Last modified:
03/04/2026

Description

Hirschmann HiOS devices versions prior to 08.1.00 and 07.1.01 contain a denial of service vulnerability in the EtherNet/IP stack where improper handling of packet length fields allows remote attackers to crash or hang the device. Attackers can send specially crafted UDP EtherNet/IP packets with a length value larger than the actual packet size to render the device inoperable.