Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat
Zeek Plugin versions d78dda6 and prior are vulnerable to out-of-bounds
write while analyzing specific Ethercat datagrams. This could allow an
attacker to cause arbitrary code execution.



Fixes

Solution

CISA recommends that users update Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Zeek Plugin to commit 3bca34c or later https://github.com/cisagov/icsnpp-ethercat .To help reduce successful exploitation, users are encouraged to keep critical software updates and patches up to date in their system networks.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-08-02T08:57:35.067Z

Reserved: 2024-02-01T17:21:11.190Z

Link: CVE-2023-7243

cve-icon Vulnrichment

Updated: 2024-08-02T08:57:35.067Z

cve-icon NVD

Status : Modified

Published: 2024-03-01T21:15:07.417

Modified: 2024-11-21T08:45:35.613

Link: CVE-2023-7243

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.