PT-2021-3969 · Hcc · Hcc Embedded Interniche

Published

2021-05-28

·

Updated

2021-08-26

·

CVE-2021-31400

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions HCC embedded InterNiche version 4.0.1
Description An issue was discovered in the tcp pulloutofband() function in tcp in.c related to the processing of out-of-band urgent-data in TCP. This issue can cause a panic function to be invoked if the pointer to the end of the out-of-band data points outside of the TCP segment's data. If the panic function had not removed a trap invocation, it would enter an infinite loop, resulting in a denial of service (DoS) through a continuous loop or a device reset.
Recommendations For HCC embedded InterNiche version 4.0.1, as a temporary workaround, consider disabling the tcp pulloutofband() function until a patch is available to prevent potential exploitation. However, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04488
CVE-2021-31400

Affected Products

Hcc Embedded Interniche