CVE-2020-25109: Critical severity ethernut nut/os vulnerability
An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. The number of DNS queries/responses (set in a DNS header) is not checked against the data present. This may lead to successful Denial-of-Service, and possibly Remote Code Execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25109?
CVE-2020-25109 has been identified as a potential Denial-of-Service vulnerability and may allow for Remote Code Execution.
How do I fix CVE-2020-25109?
To fix CVE-2020-25109, ensure that you update to the latest version of the affected software that addresses this vulnerability.
Which software is affected by CVE-2020-25109?
CVE-2020-25109 affects Ethernut in Nut/OS versions up to 5.1 and several other open-source networking products.
What type of vulnerability is CVE-2020-25109?
CVE-2020-25109 is categorized as a DNS implementation vulnerability leading to Denial-of-Service and possibly Remote Code Execution.
Can CVE-2020-25109 be exploited remotely?
Yes, CVE-2020-25109 can potentially be exploited remotely due to the nature of the DNS implementation flaw.