CVE-2020-37216: Hirschmann HiOS EtherNet/IP Stack Denial of Service
Hirschmann HiOS devices versions prior to 08.1.00 and 07.1.01 contain a denial of service vulnerability in the EtherNet/IP stack where improper handling of packet length fields allows remote attackers to crash or hang the device. Attackers can send specially crafted UDP EtherNet/IP packets with a length value larger than the actual packet size to render the device inoperable.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Hirschmann HiOS EtherNet/IP stackto a version that resolves this vulnerability.Fixed in 08.1.00 - Upgrade
Upgrade
Hirschmann HiOS EtherNet/IP stackto a version that resolves this vulnerability.Fixed in 07.1.01
Event History
Frequently Asked Questions
What is the severity of CVE-2020-37216?
CVE-2020-37216 has a severity rating of high, with a CVSS score of 8.7.
What type of vulnerability is CVE-2020-37216?
CVE-2020-37216 is a denial of service vulnerability in the Hirschmann HiOS EtherNet/IP Stack.
How do I fix CVE-2020-37216?
To mitigate CVE-2020-37216, update your Hirschmann HiOS devices to version 08.1.00 or 07.1.01 or later.
How does CVE-2020-37216 affect affected devices?
CVE-2020-37216 allows remote attackers to crash or hang affected devices by sending specially crafted UDP EtherNet/IP packets.
Are there any workarounds for CVE-2020-37216?
Currently, the recommended solution is to update to the latest software version, as no specific workarounds are provided.