CVE-2020-17437 is a high-severity vulnerability in the uIP 1.0 TCP/IP stack, affecting products like Contiki 3.0, Siemens devices, and open-iscsi. It arises when a TCP packet with the Urgent flag set contains a large Urgent pointer value, causing the stack to calculate an offset beyond its data buffer, leading to an out-of-bounds write (CWE-787). This network-exploitable flaw has a CVSS score of 8.2, indicating a high potential for impact, specifically a loss of availability and some confidentiality. While no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available and it's not on the KEV catalog, there is limited community discussion and media coverage, including a Siemens advisory.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0CPE matchmatch criteria | cpe:2.3:a:uip_project:uip:*:*:*:*:*:*:*:* | ||
<= 2.1.7CPE matchmatch criteria | cpe:2.3:a:open-iscsi_project:open-iscsi:*:*:*:*:*:*:*:* | ||
< 4.4.1CPE matchmatch criteria | cpe:2.3:o:siemens:sentron_3va_com100_firmware:*:*:*:*:*:*:*:* | ||
< 4.4.1CPE matchmatch criteria | cpe:2.3:o:siemens:sentron_3va_com800_firmware:*:*:*:*:*:*:*:* | ||
< 4.0CPE matchmatch criteria | cpe:2.3:o:siemens:sentron_3va_dsp800_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.