Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
None
Privileges Required
None
Attack Vector
Network
0

CVE-2020-27827

Disclosure Date: March 18, 2021
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
7.5 High
Impact Score:
3.6
Exploitability Score:
3.9
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
None
Integrity (I):
None
Availability (A):
High

General Information

Vendors

  • fedoraproject,
  • lldpd project,
  • openvswitch,
  • redhat,
  • siemens

Products

  • enterprise linux 7.0,
  • enterprise linux 8.0,
  • fedora 33,
  • lldpd,
  • openshift container platform 4.0,
  • openstack 10,
  • openstack 13,
  • openvswitch,
  • simatic hmi unified comfort panels firmware,
  • simatic net cp 1243-1 firmware -,
  • simatic net cp 1243-8 irc firmware -,
  • simatic net cp 1542sp-1 firmware -,
  • simatic net cp 1542sp-1 irc firmware -,
  • simatic net cp 1543-1 firmware -,
  • simatic net cp 1543sp-1 firmware -,
  • simatic net cp 1545-1 firmware -,
  • sinumerik one firmware,
  • tim 1531 irc firmware,
  • virtualization 4.0
Technical Analysis