PT-2022-10664 · Mdt · Mdt Knx Ip Interface Scn-Ip000.03+1

Published

2022-04-02

·

Updated

2022-05-03

·

CVE-2021-37740

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions MDT KNXnet/IP Secure router SCN-IP100.03 versions prior to 3.0.4 MDT KNX IP interface SCN-IP000.03 versions prior to 3.0.4
Description A denial of service issue exists in the firmware of the affected devices, allowing a remote attacker to make the device unresponsive to all requests on the KNXnet/IP Secure layer until it is rebooted. This is achieved via a SESSION REQUEST frame with a modified total length field.
Recommendations For MDT KNXnet/IP Secure router SCN-IP100.03 versions prior to 3.0.4, update to version 3.0.4 or later to resolve the issue. For MDT KNX IP interface SCN-IP000.03 versions prior to 3.0.4, update to version 3.0.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the SESSION REQUEST frame to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-37740

Affected Products

Mdt Knx Ip Interface Scn-Ip000.03
Mdt Knxnet/Ip Secure Router Scn-Ip100.03