PT-2021-2224 · Silicon · Uc/Tcp-Ip
Amine Amri
+3
·
Published
2021-03-04
·
Updated
2023-10-13
·
CVE-2020-27630
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Silicon Labs uC/TCP-IP version 3.6.0
Description
The issue is related to the improper randomness of TCP Initial Sequence Numbers (ISNs) in the stack protocol used by uC/OS and uC/TCP-IP. This could allow a remote attacker to gain unauthorized access to protected information. The problem stems from the use of insufficiently random values.
Recommendations
For Silicon Labs uC/TCP-IP version 3.6.0, consider implementing additional randomness to the TCP ISN generation process as a temporary workaround until a patch is available. Restrict access to sensitive information to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Uc/Tcp-Ip