CVE-2021-20987: Hilscher: EtherNet/IP stack crash for specific CIP service
Published Feb 16, 2021
·Updated
A denial of service and memory corruption vulnerability was found in Hilscher EtherNet/IP Core V2 prior to V2.13.0.21that may lead to code injection through network or make devices crash without recovery.
Affected Software
23 affected components
Hilscher Ethernet\/ip Adapter Firmware>=2.0<2.13.0.21
Hilscher Ethernet\/ip Adapter
Pepperl-fuchs Wcs Firmware<=1.2.1
Pepperl-fuchs Wcs3b-ls510
Pepperl-fuchs Wcs3b-ls510-om
Pepperl-fuchs Wcs3b-ls510d
Pepperl-fuchs Wcs3b-ls510d-om
Pepperl-fuchs Wcs3b-ls510dh
Pepperl-fuchs Wcs3b-ls510dh-om
Pepperl-fuchs Wcs3b-ls510h
Pepperl-fuchs Wcs3b-ls510h-om
Pepperl-fuchs Pxv100-f200-b25-v1d Firmware<=1.10.0
Pepperl-fuchs Pxv100-f200-b25-v1d
Pepperl-fuchs Pxv100i-f200-b25-v1d Firmware<=1.10.0
Pepperl-fuchs Pxv100i-f200-b25-v1d
Pepperl-fuchs Pcv100-f200-b25-v1d-6011-6720 Firmware<=1.10.0
Pepperl-fuchs Pcv100-f200-b25-v1d-6011-6720
Pepperl-fuchs Pcv50-f200-b25-v1d Firmware<=1.10.0
Pepperl-fuchs Pcv50-f200-b25-v1d
Pepperl-fuchs Pcv80-f200-b25-v1d Firmware<=1.10.0
Pepperl-fuchs Pcv80-f200-b25-v1d
Pepperl-fuchs Pcv100-f200-b25-v1d-6011 Firmware<=1.10.0
Pepperl-fuchs Pcv100-f200-b25-v1d-6011
Event History
Feb 16, 2021
CVE Published
via MITRE·04:37 PM
Data Sourced
via MITRE·04:37 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this denial of service and memory corruption vulnerability?
The vulnerability ID for this denial of service and memory corruption vulnerability is CVE-2021-20987.
2
What is the severity of CVE-2021-20987?
CVE-2021-20987 has a severity value of 8.6 (high).
3
Which software versions are affected by CVE-2021-20987?
Hilscher EtherNet/IP Core V2 prior to V2.13.0.21 is affected by CVE-2021-20987.
4
How can this vulnerability be exploited?
This vulnerability can be exploited through network to perform code injection or cause devices to crash without recovery.
5
Is Hilscher Ethernet/ip Adapter firmware vulnerable to CVE-2021-20987?
Yes, Hilscher Ethernet/ip Adapter firmware versions before V2.13.0.21 are vulnerable to CVE-2021-20987.