CVE-2020-11637: Automation Runtime TFTP Service DoS Vulnerability
Published Oct 15, 2020
·Updated
A memory leak in the TFTP service in B&R Automation Runtime versions <N4.26, <N4.34, <F4.45, <E4.53, <D4.63, <A4.73 and prior could allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition.
Affected Software
7 affected components
Br-automation Automation Runtime<=4.10
Br-automation Automation Runtime>=4.20<n4.26
Br-automation Automation Runtime>=4.40<f4.45
Br-automation Automation Runtime>=4.50<e4.53
Br-automation Automation Runtime>=4.60<d4.63
Br-automation Automation Runtime>=4.70<a4.73
Br-automation Automation Runtime>=4.30<n4.34
Event History
Oct 15, 2020
CVE Published
via MITRE·03:08 PM
Data Sourced
via MITRE·03:08 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this memory leak in the TFTP service in B&R Automation Runtime?
The vulnerability ID is CVE-2020-11637.
2
What is the severity of CVE-2020-11637?
The severity of CVE-2020-11637 is high with a severity value of 7.5.
3
Which versions of B&R Automation Runtime are affected by CVE-2020-11637?
B&R Automation Runtime versions <N4.26, <N4.34, <F4.45, <E4.53, <D4.63, <A4.73 and prior are affected by CVE-2020-11637.
4
What is the impact of CVE-2020-11637?
CVE-2020-11637 could allow an unauthenticated attacker with network access to cause a denial of service (DoS) condition.
5
Is there a fix available for CVE-2020-11637?
There is currently no available fix for CVE-2020-11637. It is recommended to apply mitigations or contact the vendor for further assistance.