ID

VAR-202011-0720


CVE

CVE-2020-27217


TITLE

Eclipse Hono  Vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2020-013704

DESCRIPTION

In Eclipse Hono version 1.3.0 and 1.4.0 the AMQP protocol adapter does not verify the size of AMQP messages received from devices. In particular, a device may send messages that are bigger than the max-message-size that the protocol adapter has indicated during link establishment. While the AMQP 1.0 protocol explicitly disallows a peer to send such messages, a hand crafted AMQP 1.0 client could exploit this behavior in order to send a message of unlimited size to the adapter, eventually causing the adapter to fail with an out of memory exception. Eclipse Hono Contains an unspecified vulnerability.Denial of service (DoS) It may be put into a state. Eclipse Hono is a software of the Eclipse Foundation used to provide a control interface for connected IOT devices. The software connects a large number of IOT devices and provides a unified access interface for external control. No detailed vulnerability details are currently provided

Trust: 2.7

sources: NVD: CVE-2020-27217 // JVNDB: JVNDB-2020-013704 // CNVD: CNVD-2021-08895 // CNNVD: CNNVD-202011-1361

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2021-08895

AFFECTED PRODUCTS

vendor:eclipsemodel:honoscope:eqversion:1.3.0

Trust: 2.4

vendor:eclipsemodel:honoscope:eqversion:1.4.0

Trust: 2.4

vendor:eclipsemodel:honoscope:eqversion: -

Trust: 0.8

sources: CNVD: CNVD-2021-08895 // JVNDB: JVNDB-2020-013704 // NVD: CVE-2020-27217

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-27217
value: HIGH

Trust: 1.0

NVD: CVE-2020-27217
value: HIGH

Trust: 0.8

CNVD: CNVD-2021-08895
value: MEDIUM

Trust: 0.6

CNNVD: CNNVD-202011-1361
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2020-27217
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2021-08895
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

nvd@nist.gov: CVE-2020-27217
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.1

Trust: 1.0

NVD: CVE-2020-27217
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2021-08895 // JVNDB: JVNDB-2020-013704 // CNNVD: CNNVD-202011-1361 // NVD: CVE-2020-27217

PROBLEMTYPE DATA

problemtype:CWE-1284

Trust: 1.0

problemtype:NVD-CWE-noinfo

Trust: 1.0

problemtype:Lack of information (CWE-noinfo) [NVD Evaluation ]

Trust: 0.8

sources: JVNDB: JVNDB-2020-013704 // NVD: CVE-2020-27217

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202011-1361

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202011-1361

PATCH

title:Bug 567068url:https://bugs.eclipse.org/bugs/show_bug.cgi?id=567068

Trust: 0.8

title:Patch for Eclipse Hono has unspecified vulnerabilitiesurl:https://www.cnvd.org.cn/patchInfo/show/246841

Trust: 0.6

title:Eclipse Hono Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=135463

Trust: 0.6

sources: CNVD: CNVD-2021-08895 // JVNDB: JVNDB-2020-013704 // CNNVD: CNNVD-202011-1361

EXTERNAL IDS

db:NVDid:CVE-2020-27217

Trust: 3.0

db:JVNDBid:JVNDB-2020-013704

Trust: 0.8

db:CNVDid:CNVD-2021-08895

Trust: 0.6

db:CNNVDid:CNNVD-202011-1361

Trust: 0.6

sources: CNVD: CNVD-2021-08895 // JVNDB: JVNDB-2020-013704 // CNNVD: CNNVD-202011-1361 // NVD: CVE-2020-27217

REFERENCES

url:https://bugs.eclipse.org/bugs/show_bug.cgi?id=567068

Trust: 2.2

url:https://nvd.nist.gov/vuln/detail/cve-2020-27217

Trust: 1.4

sources: CNVD: CNVD-2021-08895 // JVNDB: JVNDB-2020-013704 // CNNVD: CNNVD-202011-1361 // NVD: CVE-2020-27217

SOURCES

db:CNVDid:CNVD-2021-08895
db:JVNDBid:JVNDB-2020-013704
db:CNNVDid:CNNVD-202011-1361
db:NVDid:CVE-2020-27217

LAST UPDATE DATE

2024-11-23T23:11:15.201000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2021-08895date:2021-02-03T00:00:00
db:JVNDBid:JVNDB-2020-013704date:2021-07-09T09:02:00
db:CNNVDid:CNNVD-202011-1361date:2020-12-02T00:00:00
db:NVDid:CVE-2020-27217date:2024-11-21T05:20:52.770

SOURCES RELEASE DATE

db:CNVDid:CNVD-2021-08895date:2021-02-03T00:00:00
db:JVNDBid:JVNDB-2020-013704date:2021-07-09T00:00:00
db:CNNVDid:CNNVD-202011-1361date:2020-11-13T00:00:00
db:NVDid:CVE-2020-27217date:2020-11-13T20:15:16.270