Description


Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat
Zeek Plugin versions d78dda6 and prior are vulnerable to out-of-bounds
read during the process of analyzing a specific Ethercat packet. This
could allow an attacker to crash the Zeek process and leak some
information in memory.





Published: 2024-03-01
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

CISA recommends that users update Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Zeek Plugin to commit 3bca34c or later https://github.com/cisagov/icsnpp-ethercat .To help reduce successful exploitation, users are encouraged to keep critical software updates and patches up to date in their system networks.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-59423 Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Zeek Plugin versions d78dda6 and prior are vulnerable to out-of-bounds read during the process of analyzing a specific Ethercat packet. This could allow an attacker to crash the Zeek process and leak some information in memory.
History

No history.

Subscriptions

Cisa Icsnpp-ethercat
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-08-02T08:57:35.466Z

Reserved: 2024-02-01T17:20:47.493Z

Link: CVE-2023-7242

cve-icon Vulnrichment

Updated: 2024-08-02T08:57:35.466Z

cve-icon NVD

Status : Modified

Published: 2024-03-01T21:15:07.213

Modified: 2024-11-21T08:45:35.470

Link: CVE-2023-7242

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses