Description
Hirschmann HiOS devices versions prior to 08.1.00 and 07.1.01 contain a denial of service vulnerability in the EtherNet/IP stack where improper handling of packet length fields allows remote attackers to crash or hang the device. Attackers can send specially crafted UDP EtherNet/IP packets with a length value larger than the actual packet size to render the device inoperable.
Problem types
CWE-20 Improper Input Validation
Product status
>= 08.1.00 (custom)
>= 07.1.01 (custom)
05.00.00 (custom)
References
assets.belden.com/...den-Security-Bulletin-BSECV-2019-14.pdf
www.vulncheck.com/...ios-ethernet-ip-stack-denial-of-service