Unauthenticated server crash via malformed firmware-update frame
Published Aug 23, 2021 · Updated Aug 4, 2024
NULL pointer dereference in Iec104_Deal_FirmUpdate in IEC104 1.0 allows remote attackers to crash the server via a crafted firmware-update frame. The parser accepts a 43-byte firmware-update frame whose length field declares 208 bytes, then reaches a call through address zero inside the handler. No authentication or user interaction is required; processing the single malformed frame aborts the IEC104 server and interrupts its service.
Summary
What happened
NULL pointer dereference in Iec104_Deal_FirmUpdate in IEC104 1.0 allows remote attackers to crash the server via a crafted firmware-update frame. The parser accepts a 43-byte firmware-update frame whose length field declares 208 bytes, then reaches a call through address zero inside the handler. No authentication or user interaction is required; processing the single malformed frame aborts the IEC104 server and interrupts its service.
The record
- CVE
- CVE-2020-18731
- Published
- Aug 23, 2021
- Updated
- Aug 4, 2024
- Vendor
- Unknown vendor
- Product
- Unknown product
- Classifications
- CWE-476, T1499.004
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Aug 23, 2021CVE publishedPublication date reported by the CVE source.
- Aug 4, 2024Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
What conditions does exploitation require?
What is affected?
Affected products and versions are unavailable in this record.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- Firmware-update frame crash reproducerproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo