PT-2022-10664 · Mdt · Mdt Knx Ip Interface Scn-Ip000.03+1
Published
2022-04-02
·
Updated
2022-05-03
·
CVE-2021-37740
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
MDT KNXnet/IP Secure router SCN-IP100.03 versions prior to 3.0.4
MDT KNX IP interface SCN-IP000.03 versions prior to 3.0.4
Description
A denial of service issue exists in the firmware of the affected devices, allowing a remote attacker to make the device unresponsive to all requests on the KNXnet/IP Secure layer until it is rebooted. This is achieved via a
SESSION REQUEST frame with a modified total length field.Recommendations
For MDT KNXnet/IP Secure router SCN-IP100.03 versions prior to 3.0.4, update to version 3.0.4 or later to resolve the issue.
For MDT KNX IP interface SCN-IP000.03 versions prior to 3.0.4, update to version 3.0.4 or later to resolve the issue.
As a temporary workaround, consider restricting access to the
SESSION REQUEST frame to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mdt Knx Ip Interface Scn-Ip000.03
Mdt Knxnet/Ip Secure Router Scn-Ip100.03