Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2020-6084

Quick assessment

Affected
n/a Allen-Bradley
Exploitation
High exploitation probability; assess promptly
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Allen-Bradley Flex IO是美国艾伦-布拉德利(Allen-Bradley)的一个工业自动化控制系统中的远程IO套件。 Allen-Bradley Flex IO 1794-AENT/B存在安全漏洞,该漏洞源于ENIP请求路径数据段功能中存在一个可利用的拒绝服务漏洞。 攻击者可利用该漏洞导致与设备的通信中断,从而导致拒绝服务。

AI Predicted 7.5 Difficulty: Easy EPSS 4.26% · P90

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2020-6084

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
An exploitable denial of service vulnerability exists in the ENIP Request Path Logical Segment functionality of Allen-Bradley Flex IO 1794-AENT/B 4.003. A specially crafted network request can cause a loss of communications with the device resulting in denial-of-service. An attacker can send a malicious packet to trigger this vulnerability by sending an Electronic Key Segment with less bytes than required by the Key Format Table.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
未进行输入大小检查的缓冲区拷贝(传统缓冲区溢出)
Source: CVE Program / CVE List V5
Vulnerability Title
Allen-Bradley Flex IO 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Allen-Bradley Flex IO是美国艾伦-布拉德利(Allen-Bradley)的一个工业自动化控制系统中的远程IO套件。 Allen-Bradley Flex IO 1794-AENT/B存在安全漏洞,该漏洞源于ENIP请求路径数据段功能中存在一个可利用的拒绝服务漏洞。 攻击者可利用该漏洞导致与设备的通信中断,从而导致拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- Allen-Bradley Allen-Bradley Flex IO 1794-AENT/B 4.003 -

II. Public POCs for CVE-2020-6084

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2020-6084

登录查看更多情报信息。

Other References for CVE-2020-6084 (1)

Same Patch Batch · n/a · 2020-10-19 · 90 CVEs total

CVE-2020-7745 7.1 HIGH Malicious Package
CVE-2020-7159 HPE Intelligent Management Center (iMC) 安全漏洞
CVE-2020-7148 HPE Intelligent Management Center (iMC) 安全漏洞
CVE-2020-7161 HPE Intelligent Management Center (iMC) 安全漏洞
CVE-2020-7164 HPE Intelligent Management Center (iMC) 安全漏洞
CVE-2020-7165 HPE Intelligent Management Center (iMC) 安全漏洞
CVE-2020-7166 HPE Intelligent Management Center (iMC) 安全漏洞
CVE-2020-7167 HPE Intelligent Management Center 安全漏洞
CVE-2020-7169 HPE Intelligent Management Center (iMC) 安全漏洞
CVE-2020-7163 HPE Intelligent Management Center (iMC) 安全漏洞
CVE-2020-7157 HPE Intelligent Management Center (iMC) 安全漏洞
CVE-2020-7156 HPE Intelligent Management Center 安全漏洞
CVE-2020-7155 HPE Intelligent Management Center (iMC) 安全漏洞
CVE-2020-7154 HPE Intelligent Management Center (iMC) 安全漏洞
CVE-2020-7153 HPE Intelligent Management Center 安全漏洞
CVE-2020-7152 HPE Intelligent Management Center 安全漏洞
CVE-2020-7151 HPE Intelligent Management Center (iMC) 安全漏洞
CVE-2020-7150 HPE Intelligent Management Center (iMC) 安全漏洞
CVE-2020-7149 HPE Intelligent Management Center (iMC) 安全漏洞
CVE-2020-7168 HPE Intelligent Management Center (iMC) 安全漏洞

Showing top 20 of 90 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2020-6084

No comments yet


Leave a comment