CVE-2020-27827

Advisory lineage Upstream: 0 Downstream: 25
Modified
Published: 18 Mar 2021, 00:00
Last modified:03 Dec 2025, 18:20

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
0.5% LOW
1% probability +0.09%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

18 Mar 2021, 00:00
Published
Vulnerability first disclosed
03 Dec 2025, 18:20
Last Modified
Vulnerability information updated

Description

A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v2.0HIGHScore: 7.1AV:N/AC:M/Au:N/C:N/I:N/A:C

EPSS Trends

Current EPSS score: 0.50% Percentile: 67%

Techniques & Countermeasures

  • CWE-400Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

Affected Systems

  • fedoraprojectfedora

    33

  • lldpd_projectlldpd

    < 1.0.8

  • openvswitchopenvswitch

    ≥ 2.6.0, < 2.6.9 | ≥ 2.7.0, < 2.7.12 | ≥ 2.8.0, < 2.8.10 | ≥ 2.9.0, < 2.9.8 | ≥ 2.10.0, < 2.10.6 | ≥ 2.11.0, < 2.11.5 | ≥ 2.12.0, < 2.12.2 | ≥ 2.13.0, < 2.13.2 | ≥ 2.14.0, < 2.14.1

  • redhatenterprise_linux

    7.0 | 8.0

  • redhatopenshift_container_platform

    4.0

  • redhatopenstack

    10 | 13

  • redhatvirtualization

    4.0

  • siemenssimatic hmi unified comfort panels

    < 17

  • siemenssimatic_net_cp_1243-1_firmware

    na

  • siemenssimatic_net_cp_1243-8_irc_firmware

    na

  • siemenssimatic_net_cp_1542sp-1_firmware

    na

  • siemenssimatic_net_cp_1542sp-1_irc_firmware

    na

  • siemenssimatic_net_cp_1543-1_firmware

    na

  • siemenssimatic_net_cp_1543sp-1_firmware

    na

  • siemenssimatic_net_cp_1545-1_firmware

    na

  • siemenssinumerik one

    < 2.0.1

  • siemenstim 1531 irc

    < 2.2

References (8)