Security News > 2021 > April > How the NAME:WRECK Bugs Impact Consumers, Businesses

How the NAME:WRECK Bugs Impact Consumers, Businesses
2021-04-13 21:03

Researchers estimate more than 100 million internet-connected devices are vulnerable to a class of flaws dubbed NAME:WRECK. Devices ranging from smartphones, aircraft navigation systems and industrial internet of things endpoints are vulnerable to either a denial-of-service or remote code-execution attack, according to a joint report by Forescout Research Labs and JSOF Research Labs.

NAME:WRECK is similar to previous TCP/IP-DNS bugs that illustrate the complexity of the DNS protocol "That tends to yield vulnerable implementations," where bugs can often be leveraged by external attackers to take control of millions of devices simultaneously, researchers said.

One of the class of NAME:WRECK bugs are identified as DNS compression issues, impacting a wide range of devices that compress data used to communicate over the internet using TCP/IP. "With the first vulnerability, CVE-2020-27009, the attacker can craft a DNS response packet with a combination of invalid compression pointer offsets that allows them to write arbitrary data into sensitive parts of a device's memory, where they will then inject the code," researchers wrote.

CVE-2020-15795: A domain name label-parsing bug impacting devices running Nucleus NET and can lead to RCE;.

CVE-2020-27736: A VDomain name label-parsing bug impacting devices running Nucleus NET and can lead to DoS;.

CVE-2020-27737: A VDomain name label-parsing bug impacting devices running Nucleus NET and can lead to DoS;.


News URL

https://threatpost.com/namewreck-bugs-businesses/165385/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2021-04-22 CVE-2020-15795 Out-of-bounds Write vulnerability in Siemens Nucleus NET and Nucleus Source Code
A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5.5), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.20), Nucleus NET (All versions < V5.2), Nucleus Source Code (Versions including affected DNS modules), TALON TC Compact (BACnet) (All versions < V3.5.5), TALON TC Modular (BACnet) (All versions < V3.5.5).
network
high complexity
siemens CWE-787
8.1
2021-04-22 CVE-2020-27009 Out-of-bounds Write vulnerability in Siemens Nucleus NET and Nucleus Source Code
A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5.5), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.20), Nucleus NET (All versions < V5.2), Nucleus Source Code (Versions including affected DNS modules), TALON TC Compact (BACnet) (All versions < V3.5.5), TALON TC Modular (BACnet) (All versions < V3.5.5).
network
high complexity
siemens CWE-787
8.1
2021-04-22 CVE-2020-27736 Out-of-bounds Read vulnerability in Siemens products
A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5.5), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.20), Nucleus NET (All versions), Nucleus ReadyStart V3 (All versions < V2017.02.3), Nucleus ReadyStart V4 (All versions < V4.1.0), Nucleus Source Code (Versions including affected DNS modules), SIMOTICS CONNECT 400 (All versions < V0.5.0.0), TALON TC Compact (BACnet) (All versions < V3.5.5), TALON TC Modular (BACnet) (All versions < V3.5.5).
network
high complexity
siemens CWE-125
6.5
2021-04-22 CVE-2020-27737 Out-of-bounds Read vulnerability in Siemens products
A vulnerability has been identified in APOGEE PXC Compact (BACnet) (All versions < V3.5.5), APOGEE PXC Compact (P2 Ethernet) (All versions < V2.8.20), APOGEE PXC Modular (BACnet) (All versions < V3.5.5), APOGEE PXC Modular (P2 Ethernet) (All versions < V2.8.20), Nucleus NET (All versions), Nucleus ReadyStart V3 (All versions < V2017.02.3), Nucleus ReadyStart V4 (All versions < V4.1.0), Nucleus Source Code (Versions including affected DNS modules), SIMOTICS CONNECT 400 (All versions < V0.5.0.0), TALON TC Compact (BACnet) (All versions < V3.5.5), TALON TC Modular (BACnet) (All versions < V3.5.5).
network
high complexity
siemens CWE-125
6.5