← Vulnerability feed

Vulnerability record · CVE-2020-28400 · published 13 July 2021

CVE-2020-28400: Siemens dk standard ethernet controller evaluation kit firmware allocation without limits vulnerability

Siemens · Dk Standard Ethernet Controller Evaluation Kit Firmware

Affected devices contain a vulnerability that allows an unauthenticated attacker to trigger a denial of service condition. The vulnerability can be triggered if a large amount of DCP reset packets are sent to the device.

8.7 CVSS 4.0 High EPSS 1.9% · top 21.7% CWE-770 · Allocation without limits
8.7CVSS 4.0 base score, v2 5.0
1.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
79Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Affected devices contain a vulnerability that allows an unauthenticated attacker to trigger a denial of service condition. The vulnerability can be triggered if a large amount of DCP reset packets are sent to the device.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

79 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-28400 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-14491dnsmasq heap buffer overflow via crafted DNS responsednsmasq before 2.78 contains a heap-based buffer overflow (CWE-787 out-of-bounds write) triggered by a crafted DNS response. Because dnsmasq is widel…EPSS 85%analysed9.1CVE-2022-36323Siemens scalance m-800 firmware injection vulnerabilityAffected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject …EPSS 1.7%8.8CVE-2021-25667Siemens ruggedcom rm1224 firmware stack-based buffer overflow vulnerabilityA vulnerability has been identified in RUGGEDCOM RM1224 (All versions >= V4.3 and < V6.4), SCALANCE M-800 (All versions >= V4.3 and < V6.4), SCALANCE…EPSS 0.86%8.6CVE-2022-31766Siemens ruggedcom rm1224 firmware improper input validation vulnerabilityA vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.1.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK610…EPSS 1.1%7.5CVE-2022-36324Siemens scalance m-800 firmware allocation without limits vulnerabilityAffected devices do not properly handle the renegotiation of SSL/TLS parameters. This could allow an unauthenticated remote attacker to bypass the TC…EPSS 1.7%7.5CVE-2021-25676Siemens ruggedcom rm1224 firmware improper restriction of authentication attempts vulnerabilityA vulnerability has been identified in RUGGEDCOM RM1224 (V6.3), SCALANCE M-800 (V6.3), SCALANCE S615 (V6.3), SCALANCE SC-600 (All Versions >= V2.1 an…EPSS 1.3%7.5CVE-2019-13946Siemens dk standard ethernet controller uncontrolled resource consumption vulnerabilityProfinet-IO (PNIO) stack versions prior V06.00 do not properly limit internal resource allocation when multiple legitimate diagnostic package request…EPSS 1.5%7.5CVE-2018-5391Linux kernel uncontrolled resource consumption vulnerabilityThe Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-as…EPSS 32%

Source: NIST National Vulnerability Database (record CVE-2020-28400), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.