PT-2020-1259 · Siemens+10 · Simatic Cp 1243-7 Lte Eu+17

Published

2020-10-16

·

Updated

2025-09-29

·

CVE-2020-25705

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 5.10 RUGGEDCOM RM1224 versions 5.0 through 6.4 SCALANCE M-800 versions 5.0 through 6.4 SCALANCE S615 versions 5.0 through 6.4 SCALANCE SC-600 versions prior to 2.1.3 SCALANCE W1750D versions 8.3.0.1, 8.6.0, and 8.7.0 SIMATIC Cloud Connect 7 version (all versions) SIMATIC MV500 Family version (all versions) SIMATIC NET CP 1243-1 (incl. SIPLUS variants) versions 3.1.39 and later SIMATIC NET CP 1243-7 LTE EU version
Description The issue is related to a flaw in the Linux kernel's handling of ICMP packets, allowing an off-path remote attacker to bypass UDP source port randomization. This could lead to remote information disclosure with no additional execution privileges needed. The vulnerability may be exploited to quickly scan open UDP ports and potentially affect software that relies on UDP source port randomization. It is estimated that millions of users may be vulnerable to this issue.
Recommendations For Linux kernel versions prior to 5.10, update to a version 5.10 or later to resolve the issue. For RUGGEDCOM RM1224 versions 5.0 through 6.4, consider disabling the vulnerable ICMP packet handling functionality until a patch is available. For SCALANCE M-800 versions 5.0 through 6.4, restrict access to the affected UDP ports to minimize the risk of exploitation. For SCALANCE S615 versions 5.0 through 6.4, avoid using the vulnerable icmp global allow function in icmp.c until the issue is resolved. For SCALANCE SC-600 versions prior to 2.1.3, update to version 2.1.3 or later to resolve the issue. For SCALANCE W1750D versions 8.3.0.1, 8.6.0, and 8.7.0, consider applying configuration changes to restrict access to the affected UDP ports. For SIMATIC Cloud Connect 7, SIMATIC MV500 Family, and SIMATIC NET CP 1243-1 (incl. SIPLUS variants), update to a patched version or consider disabling the vulnerable functionality until a patch is available. For SIMATIC NET CP 1243-7 LTE EU, update to a version that includes the fix for this issue.

Exploit

Fix

Use of Insufficiently Random Values

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:0558
ALSA-2021_0558
ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
ALT-PU-2020-3536
ALT-PU-2020-3553
ALT-PU-2020-3571
ALT-PU-2021-1083
ALT-PU-2021-1105
ALT-PU-2021-1446
ALT-PU-2021-1621
ALT-PU-2021-1656
ALT-PU-2021-1739
ALT-PU-2021-1862
ALT-PU-2021-1866
ALT-PU-2021-1870
ASB-A-174737972
BDU:2020-05539
CESA-2021_0537
CESA-2021_0558
CESA-2021_0856
CVE-2020-25705
DLA-2483-1
DLA-2494-1
ELSA-2021-0558
ELSA-2021-0856
ELSA-2021-9002
ELSA-2021-9006
ELSA-2021-9007
MGASA-2021-0030
MGASA-2021-0031
OPENSUSE-SU-2020:1906-1
OPENSUSE-SU-2020:2034-1
OPENSUSE-SU-2020:2112-1
OPENSUSE-SU-2020:2161-1
OPENSUSE-SU-2020_2034-1
OPENSUSE-SU-2020_2112-1
OPENSUSE-SU-2020_2161-1
OPENSUSE-SU-2020_2260-1
OPENSUSE-SU-2021:0242-1
OPENSUSE-SU-2021_0242-1
OPENSUSE-SU-2024:11370-1
OPENSUSE-SU-2024:11371-1
RHSA-2021:0537
RHSA-2021:0558
RHSA-2021:0686
RHSA-2021:0765
RHSA-2021:0774
RHSA-2021:0856
RHSA-2021:0857
RHSA-2021:1531
RHSA-2021:2164
RHSA-2021:2355
RHSA-2021_0537
RHSA-2021_0558
RHSA-2021_0856
RHSA-2021_0857
SUSE-SU-2020:3273-1
SUSE-SU-2020:3281-1
SUSE-SU-2020:3326-1
SUSE-SU-2020:3484-1
SUSE-SU-2020:3491-1
SUSE-SU-2020:3501-1
SUSE-SU-2020:3503-1
SUSE-SU-2020:3507-1
SUSE-SU-2020:3512-1
SUSE-SU-2020:3513-1
SUSE-SU-2020:3522-1
SUSE-SU-2020:3532-1
SUSE-SU-2020:3544-1
SUSE-SU-2020:3651-1
SUSE-SU-2020:3670-1
SUSE-SU-2020:3690-1
SUSE-SU-2020:3717-1
SUSE-SU-2020:3764-1
SUSE-SU-2020_3326-1
SUSE-SU-2020_3484-1
SUSE-SU-2020_3491-1
SUSE-SU-2020_3501-1
SUSE-SU-2020_3503-1
SUSE-SU-2020_3507-1
SUSE-SU-2020_3513-1
SUSE-SU-2020_3522-1
SUSE-SU-2020_3532-1
SUSE-SU-2020_3544-1
SUSE-SU-2020_3651-1
SUSE-SU-2020_3670-1
SUSE-SU-2020_3690-1
SUSE-SU-2020_3717-1
SUSE-SU-2020_3748-1
USN-4657-1
USN-4658-1
USN-4658-2
USN-4659-1
USN-4680-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Linux Kernel
Ruggedcom Rm1224
Red Hat
Scalance M-800
Scalance S615
Scalance Sc-600
Scalance W1750D
Simatic Cloud Connect 7
Simatic Mv500 Family
Simatic Net Cp 1243-1
Simatic Cp 1243-7 Lte Eu
Suse
Ubuntu