First published: Tue Dec 01 2020(Updated: )
An issue was discovered in Contiki through 3.0. An Out-of-Bounds Read vulnerability exists in the uIP TCP/IP Stack component when calculating the checksums for IP packets in upper_layer_chksum in net/ipv4/uip.c.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Uip Project Uip | <=1.0 | |
Contiki-os Contiki | <=3.0 | |
Open-iscsi Project Open-iscsi | <=2.1.12 | |
Siemens Sentron 3va Com100 Firmware | <4.4.1 | |
Siemens Sentron 3va Com100 | ||
Siemens Sentron 3va Com800 Firmware | <4.4.1 | |
Siemens Sentron 3va Com800 | ||
Siemens Sentron Pac3200 Firmware | <2.4.7 | |
Siemens Sentron Pac3200 | ||
Siemens Sentron Pac4200 Firmware | <2.3.0 | |
Siemens Sentron Pac4200 | ||
ubuntu/open-iscsi | <2.1.3-1ubuntu1 | 2.1.3-1ubuntu1 |
ubuntu/open-iscsi | <2.1.3-1ubuntu1 | 2.1.3-1ubuntu1 |
ubuntu/open-iscsi | <2.0.874-5ubuntu2.11+ | 2.0.874-5ubuntu2.11+ |
ubuntu/open-iscsi | <2.0.874-7.1ubuntu6.4 | 2.0.874-7.1ubuntu6.4 |
ubuntu/open-iscsi | <2.0.873+ | 2.0.873+ |
ubuntu/open-iscsi | <2.1.3-1ubuntu1 | 2.1.3-1ubuntu1 |
ubuntu/open-iscsi | <2.1.3 | 2.1.3 |
ubuntu/open-iscsi | <2.1.3-1ubuntu1 | 2.1.3-1ubuntu1 |
ubuntu/open-iscsi | <2.1.3-1ubuntu1 | 2.1.3-1ubuntu1 |
debian/open-iscsi | <=2.0.874-7.1 | 2.1.3-5 2.1.8-1 2.1.9-3 |
All of | ||
Uip Project Uip | <=1.0 | |
Contiki-os Contiki | <=3.0 | |
All of | ||
Siemens Sentron 3va Com100 Firmware | <4.4.1 | |
Siemens Sentron 3va Com100 | ||
All of | ||
Siemens Sentron 3va Com800 Firmware | <4.4.1 | |
Siemens Sentron 3va Com800 | ||
All of | ||
Siemens Sentron Pac3200 Firmware | <2.4.7 | |
Siemens Sentron Pac3200 | ||
All of | ||
Siemens Sentron Pac4200 Firmware | <2.3.0 | |
Siemens Sentron Pac4200 | ||
Multiple (open source) picoTCP-NG, Version 1.7.0 and prior | ||
Multiple (open source) picoTCP (EOL), Version 1.7.0 and prior | ||
Multiple (open source) FNET, Version 4.6.3 | ||
Multiple (open source) Nut/Net, Version 5.1 and prior |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13987 is a vulnerability in the Contiki operating system that allows for an Out-of-Bounds Read in the uIP TCP/IP Stack component.
The vulnerability CVE-2020-13987 affects Contiki versions through 3.0, specifically in the uIP TCP/IP Stack component when calculating the checksums for IP packets in upper_layer_chksum in net/ipv4/uip.c.
The severity of the vulnerability CVE-2020-13987 is not provided in the information provided.
To fix the vulnerability CVE-2020-13987 in Contiki, it is recommended to update to a fixed version of the Contiki operating system when available.
More information about the vulnerability CVE-2020-13987 can be found on the official websites such as the US-CERT, CERT, and Siemens CERT portals.