First published: Mon Feb 15 2021(Updated: )
In Hilscher rcX RTOS versions prios to V2.1.14.1 the actual UDP packet length is not verified against the length indicated by the packet. This may lead to a denial of service of the affected device.
Credit: info@cert.vde.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hilscher rcX RTOS | <2.1.14.1 | |
Pepperl-fuchs Ice1-16di-g60l-v1d Firmware | <=f10017 | |
Pepperl-fuchs Ice1-16di-g60l-v1d | ||
Pepperl-fuchs Ice1-16dio-g60l-c1-v1d Firmware | <=f10017 | |
Pepperl-fuchs Ice1-16dio-g60l-c1-v1d | ||
Pepperl-fuchs Ice1-16dio-g60l-v1d Firmware | <=f10017 | |
Pepperl-fuchs Ice1-16dio-g60l-v1d | ||
Pepperl-fuchs Ice1-8di8do-g60l-c1-v1d Firmware | <=f10017 | |
Pepperl-fuchs Ice1-8di8do-g60l-c1-v1d | ||
Pepperl-fuchs Ice1-8di8do-g60l-v1d Firmware | <=f10017 | |
Pepperl-fuchs Ice1-8di8do-g60l-v1d | ||
Pepperl-fuchs Ice1-8iol-g30l-v1d Firmware | <=f10017 | |
Pepperl-fuchs Ice1-8iol-g30l-v1d | ||
Pepperl-fuchs Ice1-8iol-g60l-v1d Firmware | <=f10017 | |
Pepperl-fuchs Ice1-8iol-g60l-v1d | ||
Pepperl-fuchs Ice1-8iol-s2-g60l-v1d Firmware | <=f10017 | |
Pepperl-fuchs Ice1-8iol-s2-g60l-v1d |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20988 is a vulnerability in Hilscher rcX RTOS versions prior to V2.1.14.1 that allows for a denial of service attack.
CVE-2021-20988 has a severity rating of 7.5 (High).
Hilscher rcX RTOS versions up to and excluding V2.1.14.1 are affected by CVE-2021-20988.
To fix CVE-2021-20988, update your Hilscher rcX RTOS to version V2.1.14.1 or higher.
You can find more information about CVE-2021-20988 at the following references: [link 1](https://cert.vde.com/de-de/advisories/vde-2021-018) and [link 2](https://kb.hilscher.com/display/ISMS/2019-04-10+Wrong+handling+of+the+UDP+checksum).