{
    "document": {
        "acknowledgments": [
            {
                "organization": "CERT@VDE",
                "summary": "coordination",
                "urls": [
                    "https://certvde.com"
                ]
            },
            {
                "summary": "reported",
                "organization": "Claroty",
                "names": [
                    " Sharon Brizinov"
                ]
            }
        ],
        "category": "csaf_security_advisory",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE",
                "url": "https://www.first.org/tlp/"
            }
        },
        "lang": "en-US",
        "notes": [
            {
                "category": "summary",
                "text": "Promass 83 devices utilizing 499ES EtherNet/IP (ENIP) Stack by Real Time Automation (RTA) are vulnerable to a stack-based buffer overflow.\n\nUpdate A, 2021-10-07:\n\nadded credits\nchanged title from \"ENDRESS+HAUSER: Promass 83 with Ether/IP affected by DoS vulnerability\" to \"ENDRESS+HAUSER: Promass 83 with EtherNet/IP affected by a stack-based buffer overflow\"",
                "title": "Summary"
            },
            {
                "category": "description",
                "text": "The vulnerability described can lead to a denial of service or even remote code execution.",
                "title": "Impact"
            },
            {
                "category": "description",
                "title": "Mitigation",
                "text": "If an immediate firmware update is not possible, the only way to prevent an attack is to disable communication via EtherNet/IP."
            },
            {
                "title": "Remediation",
                "text": "Endress+Hauser provides updated firmware versions (Firmware versions >1.00.00) for the related product from the Proline portfolio which fixes the vulnerability. Endress+Hauser strongly recommends customers to update to the new fixed version. For support, please contact your local service center.",
                "category": "description"
            }
        ],
        "publisher": {
            "category": "vendor",
            "contact_details": "psirt@endress.com",
            "name": "Endress+Hauser AG",
            "namespace": "https://www.endress.com"
        },
        "references": [
            {
                "category": "external",
                "summary": "Endress+Hauser advisory overview at CERT@VDE",
                "url": "https://certvde.com/de/advisories/vendor/endress+hauser/"
            },
            {
                "category": "self",
                "summary": "VDE-2021-040: Endress+Hauser: Promass 83 with EtherNet/IP affected by a stack-based buffer overflow - HTML",
                "url": "https://certvde.com/en/advisories/VDE-2021-040"
            },
            {
                "summary": "VDE-2021-040: Endress+Hauser: Promass 83 with EtherNet/IP affected by a stack-based buffer overflow - CSAF",
                "url": "https://endress-hauser.csaf-tp.certvde.com/.well-known/csaf/white/2021/vde-2021-040.json",
                "category": "self"
            }
        ],
        "title": "Endress+Hauser: Promass 83 with EtherNet/IP affected by a stack-based buffer overflow",
        "tracking": {
            "aliases": [
                "VDE-2021-040"
            ],
            "current_release_date": "2025-05-14T12:28:19.000Z",
            "generator": {
                "date": "2025-01-22T15:06:26.010Z",
                "engine": {
                    "name": "Secvisogram",
                    "version": "2.5.17"
                }
            },
            "id": "VDE-2021-040",
            "initial_release_date": "2021-10-04T12:30:00.000Z",
            "revision_history": [
                {
                    "date": "2021-10-04T12:30:00.000Z",
                    "number": "1",
                    "summary": "Initial revision."
                },
                {
                    "date": "2021-10-07T10:00:00.000Z",
                    "number": "2",
                    "summary": "Update A"
                },
                {
                    "number": "3",
                    "summary": "Fix: firmware category, added distribution",
                    "date": "2025-05-14T12:28:19.000Z"
                }
            ],
            "status": "final",
            "version": "3"
        }
    },
    "product_tree": {
        "branches": [
            {
                "category": "vendor",
                "name": "Endress+Hauser",
                "branches": [
                    {
                        "category": "product_family",
                        "name": "Hardware",
                        "branches": [
                            {
                                "name": "Promass 83",
                                "category": "product_name",
                                "product": {
                                    "name": "Promass 83",
                                    "product_id": "CSAFPID-11001"
                                }
                            }
                        ]
                    },
                    {
                        "name": "Firmware",
                        "category": "product_family",
                        "branches": [
                            {
                                "name": "1.00.00",
                                "category": "product_version",
                                "product": {
                                    "name": "Firmware 1.00.00",
                                    "product_id": "CSAFPID-21001"
                                }
                            },
                            {
                                "name": ">1.00.00",
                                "category": "product_version_range",
                                "product": {
                                    "name": "Firmware >1.00.00",
                                    "product_id": "CSAFPID-22001"
                                }
                            }
                        ]
                    }
                ]
            }
        ],
        "relationships": [
            {
                "relates_to_product_reference": "CSAFPID-11001",
                "category": "installed_on",
                "product_reference": "CSAFPID-21001",
                "full_product_name": {
                    "name": "Firmware 1.00.00 installed on Promass 83",
                    "product_id": "CSAFPID-31001"
                }
            },
            {
                "category": "installed_on",
                "product_reference": "CSAFPID-22001",
                "relates_to_product_reference": "CSAFPID-11001",
                "full_product_name": {
                    "name": "Firmware >1.00.00 installed on Promass 83",
                    "product_id": "CSAFPID-32001"
                }
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2020-25159",
            "title": "CVE-2020-25159",
            "cwe": {
                "id": "CWE-121",
                "name": "Stack-based Buffer Overflow"
            },
            "notes": [
                {
                    "title": "Vulnerability Description",
                    "category": "description",
                    "text": "The install.c module in the Pengutronix RAUC update client prior to version 1.5 has a Time-of-Check Time-of-Use vulnerability, where signature verification on an update file takes place before the file is reopened for installation. An attacker who can modify the update file just before it is reopened can install arbitrary code on the device."
                }
            ],
            "product_status": {
                "known_affected": [
                    "CSAFPID-31001"
                ],
                "fixed": [
                    "CSAFPID-32001"
                ]
            },
            "remediations": [
                {
                    "details": "If an immediate firmware update is not possible, the only way to prevent an attack is to disable communication via EtherNet/IP.",
                    "category": "mitigation",
                    "product_ids": [
                        "CSAFPID-31001"
                    ]
                },
                {
                    "details": "Endress+Hauser provides updated firmware versions (Firmware versions >1.00.00) for the related product from the Proline portfolio which fixes the vulnerability. Endress+Hauser strongly recommends customers to update to the new fixed version. For support, please contact your local service center.",
                    "category": "vendor_fix",
                    "product_ids": [
                        "CSAFPID-31001"
                    ]
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "temporalScore": 9.8,
                        "temporalSeverity": "CRITICAL",
                        "environmentalScore": 9.8,
                        "environmentalSeverity": "CRITICAL",
                        "attackVector": "NETWORK",
                        "attackComplexity": "LOW",
                        "privilegesRequired": "NONE",
                        "userInteraction": "NONE",
                        "scope": "UNCHANGED",
                        "confidentialityImpact": "HIGH",
                        "integrityImpact": "HIGH",
                        "availabilityImpact": "HIGH"
                    },
                    "products": [
                        "CSAFPID-31001"
                    ]
                }
            ]
        }
    ]
}