{"id":"CVE-2020-37216","title":"Hirschmann HiOS devices versions prior to 08.1.00 and 07.1.01  contain a denial of service vulnerability in the EtherNet/IP stack where improper handling of packet length fields allows remote attackers to crash or hang the device","summary":"Hirschmann HiOS devices versions prior to 08.1.00 and 07.1.01  contain a denial of service vulnerability in the EtherNet/IP stack where improper handling of packet length fields allows remote attackers to crash or hang the device. Attack…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-20"],"published":"2026-04-03","updated":"2026-07-24","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-37216","references":[{"url":"https://assets.belden.com/m/3d3e2cbfa4860258/original/Belden-Security-Bulletin-BSECV-2019-14.pdf","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/hirschmann-hios-ethernet-ip-stack-denial-of-service","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"epss":0.00921,"epssPercentile":0.58795,"ingestedAt":"2026-07-25T22:05:04.558Z","slug":"CVE-2020-37216","body":"## Overview\n\nHirschmann HiOS devices versions prior to 08.1.00 and 07.1.01  contain a denial of service vulnerability in the EtherNet/IP stack where improper handling of packet length fields allows remote attackers to crash or hang the device. Attackers can send specially crafted UDP EtherNet/IP packets with a length value larger than the actual packet size to render the device inoperable.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}