CVE-2020-35683 is a Denial-of-Service vulnerability in HCC Nichestack 3.0, affecting various Siemens industrial control devices. It arises from unchecked IP payload size values during ICMP checksum computation, leading to out-of-bounds reads. With a CVSS score of 7.5 (HIGH), this vulnerability is network-exploitable with low attack complexity, requiring no user interaction or privileges, and can cause a complete loss of availability. There is no evidence of active exploitation, and public exploit code is unavailable, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0CPE matchmatch criteria | cpe:2.3:a:hcc-embedded:nichestack:3.0:*:*:*:*:*:*:* | ||
< 3.0.4CPE matchmatch criteria | cpe:2.3:o:siemens:7km9300-0ae02-0aa0_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.