CVE-2020-6084

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
19/10/2020
Last modified:
29/07/2022

Description

An exploitable denial of service vulnerability exists in the ENIP Request Path Logical Segment functionality of Allen-Bradley Flex IO 1794-AENT/B 4.003. A specially crafted network request can cause a loss of communications with the device resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability by sending an Electronic Key Segment with less bytes than required by the Key Format Table.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:rockwellautomation:flex_i\/o_1794-aent:4.003:*:*:*:*:*:*:*
cpe:2.3:h:rockwellautomation:flex_i\/o_1794-aent:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools