CVE-2020-22552 Information
Feb 14, 2021
cve
Description
The Snap7 server component in version 1.4.1 when an attacker sends a crafted packet with COTP protocol the last-data-unit flag set to No and S7 writes a var function the Snap7 server will be crashed.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Reference
http://snap7.com https://sourceforge.net/p/snap7/discussion/bugfix/thread/456d76fdde/ https://sourceforge.net/projects/snap7/
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
HIGH
Base Severity
7.5
Share on: