Apache PLC4X - PLC4C (Only the C language implementation was effected) was vulnerable to an unsigned integer underflow flaw inside the tcp transport. Users should update to 0.9.1, which addresses this issue. However, in order to exploit this vulnerability, a user would have to actively connect to a mallicious device which could send a response with invalid content. Currently we consider the probability of this being exploited as quite minimal, however this could change in the future, especially with the industrial networks growing more and more together.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-30036 Apache PLC4X - PLC4C (Only the C language implementation was effected) was vulnerable to an unsigned integer underflow flaw inside the tcp transport. Users should update to 0.9.1, which addresses this issue. However, in order to exploit this vulnerability, a user would have to actively connect to a mallicious device which could send a response with invalid content. Currently we consider the probability of this being exploited as quite minimal, however this could change in the future, especially with the industrial networks growing more and more together.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-08-04T03:47:13.291Z

Reserved: 2021-10-30T00:00:00

Link: CVE-2021-43083

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-12-19T09:15:06.633

Modified: 2024-11-21T06:28:39.557

Link: CVE-2021-43083

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.