CVE-2016-20009: Siemens Sgt-100 Firmware

Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.

A DNS client stack-based buffer overflow in ipdnsc_decode_name() affects Wind River VxWorks 6.5 through 7. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

Affected products

  • Siemens Sgt-100 Firmware: any version
  • Siemens Sgt-200 Firmware: any version
  • Siemens Sgt-300 Firmware: any version
  • Siemens Sgt-400 Firmware: any version
  • Siemens Sgt-a20 Firmware: any version
  • Siemens Sgt-a35 Firmware: any version
  • Siemens Sgt-a65 Firmware: any version
  • Windriver Vxworks: from 6.5, up to and including 7.0

Published 2021-03-11. Last modified 2026-06-17.