CVE-2020-27827

A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.
References
Link Resource
https://bugzilla.redhat.com/show_bug.cgi?id=1921438 Issue Tracking Mitigation Patch Third Party Advisory
https://mail.openvswitch.org/pipermail/ovs-dev/2021-January/379471.html Mailing List Mitigation Vendor Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-941426.pdf Patch Third Party Advisory
https://us-cert.cisa.gov/ics/advisories/icsa-21-194-07 Third Party Advisory US Government Resource
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:lldpd_project:lldpd:*:*:*:*:*:*:*:*
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*
cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:virtualization:4.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:10:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:13:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:siemens:simatic_hmi_unified_comfort_panels_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_hmi_unified_comfort_panels:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:siemens:simatic_net_cp_1243-1_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_net_cp_1243-1:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:siemens:simatic_net_cp_1243-8_irc_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_net_cp_1243-8_irc:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:siemens:simatic_net_cp_1542sp-1_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_net_cp_1542sp-1:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:siemens:simatic_net_cp_1542sp-1_irc_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_net_cp_1542sp-1_irc:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:siemens:simatic_net_cp_1543-1_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_net_cp_1543-1:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:siemens:simatic_net_cp_1543sp-1_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_net_cp_1543sp-1:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:siemens:simatic_net_cp_1545-1_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_net_cp_1545-1:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:siemens:tim_1531_irc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:tim_1531_irc:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:siemens:sinumerik_one_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:sinumerik_one:-:*:*:*:*:*:*:*

Information

Published : 2021-03-18 10:15

Updated : 2022-10-06 19:53


NVD link : CVE-2020-27827

Mitre link : CVE-2020-27827


JSON object : View

CWE
CWE-400

Uncontrolled Resource Consumption

Advertisement

dedicated server usa

Products Affected

openvswitch

  • openvswitch

lldpd_project

  • lldpd

siemens

  • simatic_net_cp_1543-1
  • simatic_net_cp_1543-1_firmware
  • simatic_hmi_unified_comfort_panels_firmware
  • simatic_hmi_unified_comfort_panels
  • simatic_net_cp_1243-1
  • simatic_net_cp_1542sp-1_irc
  • tim_1531_irc_firmware
  • simatic_net_cp_1543sp-1
  • simatic_net_cp_1542sp-1_irc_firmware
  • sinumerik_one_firmware
  • simatic_net_cp_1542sp-1
  • simatic_net_cp_1543sp-1_firmware
  • simatic_net_cp_1243-8_irc
  • simatic_net_cp_1243-1_firmware
  • simatic_net_cp_1542sp-1_firmware
  • simatic_net_cp_1545-1_firmware
  • simatic_net_cp_1545-1
  • sinumerik_one
  • tim_1531_irc
  • simatic_net_cp_1243-8_irc_firmware

redhat

  • enterprise_linux
  • openstack
  • virtualization
  • openshift_container_platform

fedoraproject

  • fedora