CVE-2020-25927 is an out-of-bounds read vulnerability in the DNS feature of InterNiche NicheStack TCP/IP 4.0.1, specifically within the dns_upcall() function. This flaw allows a remote attacker to trigger a denial of service by sending a specially crafted DNS response packet that does not properly align with the header's query/response count. Rated 7.5 HIGH on CVSS, the attack requires no user interaction or prior authentication. While not actively exploited in the wild and lacking public exploit code, it has garnered some community discussion and media coverage due to its impact on critical industrial control devices.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0.1CPE matchmatch criteria | cpe:2.3:a:hcc-embedded:nichestack_tcp\/ip:4.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.