CVE-2020-25107: Critical severity ethernut nut/os vulnerability
An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. There is no check on whether a domain name has '\0' termination. This may lead to successful Denial-of-Service, and possibly Remote Code Execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25107?
CVE-2020-25107 has the potential for Denial-of-Service and possibly Remote Code Execution, making it a significant vulnerability.
How do I fix CVE-2020-25107?
To fix CVE-2020-25107, ensure that domain names are properly checked for '\0' termination before processing.
Which software is affected by CVE-2020-25107?
CVE-2020-25107 affects Nut/OS 5.1, uIP-Contiki-OS versions 3.0 and prior, uIP-Contiki-NG versions 4.5 and prior, and several other open-source products.
Can CVE-2020-25107 be exploited remotely?
Yes, CVE-2020-25107 can potentially be exploited remotely, as the vulnerability is related to DNS implementation.
Is there a patch available for CVE-2020-25107?
Check the respective vendors for a patch, as remediation steps may differ based on the specific affected software.