CVE-2020-28393: High severity siemens scalance xm400 vulnerability
An unauthenticated remote attacker could create a permanent denial-of-service condition by sending specially crafted OSPF packets. Successful exploitation requires OSPF to be enabled on an affected device on the SCALANCE XM-400, XR-500 (All versions prior to v6.4).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-28393?
CVE-2020-28393 is a vulnerability that could allow an unauthenticated remote attacker to create a permanent denial-of-service condition on affected Siemens SCALANCE XM-400 and XR-500 devices prior to version 6.4.
How severe is CVE-2020-28393?
CVE-2020-28393 has a severity value of 7.5, indicating a high severity.
Which devices are affected by CVE-2020-28393?
Siemens SCALANCE XM-400 and XR-500 devices prior to version 6.4 are affected by CVE-2020-28393.
How can an attacker exploit CVE-2020-28393?
An unauthenticated remote attacker can exploit CVE-2020-28393 by sending specially crafted OSPF packets.
Are there any fixes available for CVE-2020-28393?
The affected devices can be fixed by updating to version 6.4 of Siemens SCALANCE XM-400 and XR-500 firmware.