Learn about CVE-2020-28393, an incorrect calculation vulnerability on SCALANCE XM-400, XR-500 devices. Find out the impact, affected versions, and mitigation steps.
An unauthenticated remote attacker could create a permanent denial-of-service condition by sending specially crafted OSPF packets on SCALANCE XM-400, XR-500 devices (All versions prior to v6.4).
Understanding CVE-2020-28393
This CVE involves an incorrect calculation vulnerability that could lead to a denial-of-service attack on affected devices.
What is CVE-2020-28393?
CVE-2020-28393 is a vulnerability that allows an unauthenticated remote attacker to trigger a denial-of-service condition by sending malicious OSPF packets to SCALANCE XM-400, XR-500 devices running versions prior to v6.4.
The Impact of CVE-2020-28393
The exploitation of this vulnerability could result in a permanent denial-of-service condition on the affected devices, disrupting network operations and potentially causing downtime.
Technical Details of CVE-2020-28393
This section provides more in-depth technical details about the vulnerability.
Vulnerability Description
The vulnerability is due to an incorrect calculation in the affected devices, allowing attackers to exploit OSPF functionality to cause a denial-of-service condition.
Affected Systems and Versions
Exploitation Mechanism
Successful exploitation of this vulnerability requires OSPF to be enabled on the affected SCALANCE XM-400, XR-500 devices running versions prior to v6.4.
Mitigation and Prevention
Protecting systems from CVE-2020-28393 involves taking immediate and long-term security measures.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates