CVE-2021-20987 is a critical denial of service and memory corruption vulnerability affecting Hilscher EtherNet/IP Core V2 prior to V2.13.0.21, and consequently products from Hilscher and Pepperl-Fuchs utilizing this core. With a CVSS score of 8.6 (HIGH), this vulnerability can be exploited remotely with low attack complexity, potentially leading to device crashes without recovery or even code injection. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0, < 2.13.0.21CPE matchmatch criteria | cpe:2.3:o:hilscher:ethernet\/ip_adapter_firmware:*:*:*:*:*:*:*:* | ||
<= 1.2.1CPE matchmatch criteria | cpe:2.3:o:pepperl-fuchs:wcs_firmware:*:*:*:*:*:*:*:* | ||
<= 1.10.0CPE matchmatch criteria | cpe:2.3:o:pepperl-fuchs:pxv100-f200-b25-v1d_firmware:*:*:*:*:*:*:*:* | ||
<= 1.10.0CPE matchmatch criteria | cpe:2.3:o:pepperl-fuchs:pxv100i-f200-b25-v1d_firmware:*:*:*:*:*:*:*:* | ||
<= 1.10.0CPE matchmatch criteria | cpe:2.3:o:pepperl-fuchs:pcv100-f200-b25-v1d-6011-6720_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Denial of Service in Rexroth ActiveMover using EtherNet/IP protocol
Mar 31, 2021Denial of Service in Rexroth ActiveMover using EtherNet/IP protocol
Mar 31, 2021Denial of Service in Rexroth ActiveMover using EtherNet/IP protocol
Mar 31, 2021Denial of Service in Rexroth ActiveMover using EtherNet/IP protocol
Mar 31, 2021Denial of Service in Rexroth ActiveMover using EtherNet/IP protocol
Mar 31, 2021Denial of Service in Rexroth ActiveMover using EtherNet/IP protocol
Mar 31, 2021