SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-27541

Denial of Service vulnerability in Rostelecom CS-C2SHW 5.0.082.1.

HIGH 7.5EPSS 1.11%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.11%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Denial of Service vulnerability in Rostelecom CS-C2SHW 5.0.082.1. AgentGreen service has a bug in parsing broadcast discovery UDP packet. Sending a packet of too small size will lead to an attempt of allocating buffer of negative size. As the result service AgentGreen will be terminated and started again later.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
1.11% probability · 64th percentile
CISA KEV
Not listed
Weakness
CWE-787
Affected
company/cs-c2shw firmware
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.