CVE-2020-27827
Estado: ModificadaAlta (7.5)—
A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 3.23%
- Percentil entre todas las CVEs puntuadas: 88
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (17)
Fedoraproject — FedoraLldpd Project — LldpdOpenvswitch — OpenvswitchRedhat — Enterprise LinuxRedhat — Openshift Container PlatformRedhat — OpenstackRedhat — VirtualizationSiemens — Simatic HMI Unified Comfort Panels FirmwareSiemens — Simatic NET CP 1243-1 FirmwareSiemens — Simatic NET CP 1243-8 IRC FirmwareSiemens — Simatic NET CP 1542sp-1 FirmwareSiemens — Simatic NET CP 1542sp-1 IRC FirmwareSiemens — Simatic NET CP 1543-1 FirmwareSiemens — Simatic NET CP 1543sp-1 FirmwareSiemens — Simatic NET CP 1545-1 FirmwareSiemens — Sinumerik ONE FirmwareSiemens — TIM 1531 IRC Firmware
CWE
- CWE-400
Referencias
- https://bugzilla.redhat.com/show_bug.cgi?id=1921438
- https://cert-portal.siemens.com/productcert/pdf/ssa-941426.pdf
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3T5XHPOGIPWCRRPJUE6P3HVC5PTSD5JS/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JYA4AMJXCNF6UPFG36L2TPPT32C242SP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SKQWHG2SZJZSGC7PXVDAEJYBN7ESDR7D/
- https://mail.openvswitch.org/pipermail/ovs-dev/2021-January/379471.html
- https://security.gentoo.org/glsa/202311-16
- https://us-cert.cisa.gov/ics/advisories/icsa-21-194-07
- https://bugzilla.redhat.com/show_bug.cgi?id=1921438
- https://cert-portal.siemens.com/productcert/pdf/ssa-941426.pdf
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3T5XHPOGIPWCRRPJUE6P3HVC5PTSD5JS/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JYA4AMJXCNF6UPFG36L2TPPT32C242SP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SKQWHG2SZJZSGC7PXVDAEJYBN7ESDR7D/
- https://mail.openvswitch.org/pipermail/ovs-dev/2021-January/379471.html
- https://security.gentoo.org/glsa/202311-16
- https://us-cert.cisa.gov/ics/advisories/icsa-21-194-07
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-27827",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2020-27827",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-06-04T13:38:48.935265Z"
}
}
],
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.1,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:C",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 6.9,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "lldp/openvswitch",
"versions": [
{
"status": "affected",
"version": "lldpd 1.0.8, openvswitch 2.14.1, openvswitch 2.13.2, openvswitch 2.12.2, openvswitch 2.11.5, openvswitch 2.10.6, openvswitch 2.9.8, openvswitch 2.8.10, openvswitch 2.7.12, openvswitch 2.6.9"
}
]
}
]
}
],
"published": "2021-03-18T17:15:13.510",
"references": [
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1921438",
"tags": [
"Issue Tracking",
"Mitigation",
"Patch",
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-941426.pdf",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3T5XHPOGIPWCRRPJUE6P3HVC5PTSD5JS/",
"source": "secalert@redhat.com"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JYA4AMJXCNF6UPFG36L2TPPT32C242SP/",
"source": "secalert@redhat.com"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SKQWHG2SZJZSGC7PXVDAEJYBN7ESDR7D/",
"source": "secalert@redhat.com"
},
{
"url": "https://mail.openvswitch.org/pipermail/ovs-dev/2021-January/379471.html",
"tags": [
"Mailing List",
"Mitigation",
"Vendor Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://security.gentoo.org/glsa/202311-16",
"source": "secalert@redhat.com"
},
{
"url": "https://us-cert.cisa.gov/ics/advisories/icsa-21-194-07",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "secalert@redhat.com"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1921438",
"tags": [
"Issue Tracking",
"Mitigation",
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-941426.pdf",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3T5XHPOGIPWCRRPJUE6P3HVC5PTSD5JS/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JYA4AMJXCNF6UPFG36L2TPPT32C242SP/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SKQWHG2SZJZSGC7PXVDAEJYBN7ESDR7D/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://mail.openvswitch.org/pipermail/ovs-dev/2021-January/379471.html",
"tags": [
"Mailing List",
"Mitigation",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://security.gentoo.org/glsa/202311-16",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://us-cert.cisa.gov/ics/advisories/icsa-21-194-07",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "secalert@redhat.com",
"description": [
{
"lang": "en",
"value": "CWE-400"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability."
},
{
"lang": "es",
"value": "Se encontró un fallo en múltiples versiones de OpenvSwitch. Los paquetes LLDP especialmente diseñados pueden causar que una memoria se pierda cuando se asignan datos para manejar TLV opcionales específicos, potencialmente causando una denegación de servicio. La mayor amenaza de esta vulnerabilidad es la disponibilidad del sistema"
}
],
"lastModified": "2026-06-17T03:09:41.710",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:lldpd_project:lldpd:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "60E35B97-6AAD-4F2D-88E7-D1B235D36E63",
"versionEndExcluding": "1.0.8"
},
{
"criteria": "cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D7946D64-A914-4DC4-8AFA-E5A4C9415B87",
"versionEndExcluding": "2.6.9",
"versionStartIncluding": "2.6.0"
},
{
"criteria": "cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FCBC3BDE-1CFE-4275-8F33-BC7D0ECD88BA",
"versionEndExcluding": "2.7.12",
"versionStartIncluding": "2.7.0"
},
{
"criteria": "cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F553884B-6DC9-4DBD-ADD6-B24B8A9FDFBA",
"versionEndExcluding": "2.8.10",
"versionStartIncluding": "2.8.0"
},
{
"criteria": "cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4A42E11A-8575-40B1-8343-840783E17FD0",
"versionEndExcluding": "2.9.8",
"versionStartIncluding": "2.9.0"
},
{
"criteria": "cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "92DE8269-BD35-46B7-B4D0-5C0B5C3B2BE5",
"versionEndExcluding": "2.10.6",
"versionStartIncluding": "2.10.0"
},
{
"criteria": "cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6AA97E08-3F7E-46CE-B03D-FD06307137A8",
"versionEndExcluding": "2.11.5",
"versionStartIncluding": "2.11.0"
},
{
"criteria": "cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F74931FC-4B61-4EAD-90CD-D095A9BC76B6",
"versionEndExcluding": "2.12.2",
"versionStartIncluding": "2.12.0"
},
{
"criteria": "cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6AACFC3E-4242-4E9E-9AC2-B2E1C700DF0C",
"versionEndExcluding": "2.13.2",
"versionStartIncluding": "2.13.0"
},
{
"criteria": "cpe:2.3:a:openvswitch:openvswitch:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E22360F8-FD09-4CED-8E62-46916AB17A12",
"versionEndExcluding": "2.14.1",
"versionStartIncluding": "2.14.0"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "932D137F-528B-4526-9A89-CD59FA1AB0FE"
},
{
"criteria": "cpe:2.3:a:redhat:openstack:10:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E722FEF7-58A6-47AD-B1D0-DB0B71B0C7AA"
},
{
"criteria": "cpe:2.3:a:redhat:openstack:13:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "704CFA1A-953E-4105-BFBE-406034B83DED"
},
{
"criteria": "cpe:2.3:a:redhat:virtualization:4.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6BBD7A51-0590-4DDF-8249-5AFA8D645CB6"
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "142AD0DD-4CF3-4D74-9442-459CE3347E3A"
},
{
"criteria": "cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F4CFF558-3C47-480D-A2F0-BABF26042943"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E460AA51-FCDA-46B9-AE97-E6676AA5E194"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:siemens:simatic_hmi_unified_comfort_panels_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CAB60054-8FD0-45A4-B7DC-FFF061764B80",
"versionEndExcluding": "17"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:siemens:simatic_hmi_unified_comfort_panels:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2921C017-7617-4789-9690-C81EAC4F469D"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:siemens:simatic_net_cp_1243-1_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "238D992C-6158-4E31-AE0A-7A9C54B51963"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:siemens:simatic_net_cp_1243-1:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "65278BA0-3C81-4D81-9801-D7BE3A1D7680"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:siemens:simatic_net_cp_1243-8_irc_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2009C1FA-96D5-413C-9161-0DB55F841088"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:siemens:simatic_net_cp_1243-8_irc:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "350FD323-C876-4C7A-A2E7-4B0660C87F6C"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:siemens:simatic_net_cp_1542sp-1_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F56E0C04-AEC3-45C8-93E7-FCA3B7F370F6"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:siemens:simatic_net_cp_1542sp-1:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "0602DEEA-AE39-4A44-9D78-6623943DDCD6"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:siemens:simatic_net_cp_1542sp-1_irc_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1F7747CD-757E-4B36-8F23-7588183948A7"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:siemens:simatic_net_cp_1542sp-1_irc:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "C1EE2F10-A7A6-486F-AE5C-53AE25BAF200"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:siemens:simatic_net_cp_1543-1_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BB5A494F-2EAB-4647-9A45-5CB0C382E099"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:siemens:simatic_net_cp_1543-1:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "F56C2BDC-928E-491A-8E7C-F976B3787C7A"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:siemens:simatic_net_cp_1543sp-1_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "98C894B9-C62A-4689-9DA4-D9A3795B8CE5"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:siemens:simatic_net_cp_1543sp-1:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "783B50B8-2FB7-4982-88AA-B4F2AD094796"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:siemens:simatic_net_cp_1545-1_firmware:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7A46FF27-6B0D-4606-9D7B-45912556416F"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:siemens:simatic_net_cp_1545-1:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1256EB4B-DD8A-4F99-AE69-F74E8F789C63"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:siemens:tim_1531_irc_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D5B1898E-CB50-429B-9609-DC27C33C5C37",
"versionEndExcluding": "2.2"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:siemens:tim_1531_irc:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "C1D94BEB-BBFB-4258-9835-87DBBB999239"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:siemens:sinumerik_one_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "296D097F-C7D2-4D12-8621-E0D1CAE64FA1",
"versionEndExcluding": "2.0.1"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:siemens:sinumerik_one:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "AE30FFDF-5494-400D-8F88-954A6B1503B9"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "secalert@redhat.com"
}