Zeek Plugin versions d78dda6 and prior are vulnerable to out-of-bounds
write in their primary analyses function for Ethercat communication
packets. This could allow an attacker to cause arbitrary code execution.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-59425 | Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Zeek Plugin versions d78dda6 and prior are vulnerable to out-of-bounds write in their primary analyses function for Ethercat communication packets. This could allow an attacker to cause arbitrary code execution. |
Solution
CISA recommends that users update Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Zeek Plugin to commit 3bca34c or later https://github.com/cisagov/icsnpp-ethercat .To help reduce successful exploitation, users are encouraged to keep critical software updates and patches up to date in their system networks.
Workaround
No workaround given by the vendor.
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-08-05T13:13:35.428Z
Reserved: 2024-02-01T17:21:33.223Z
Link: CVE-2023-7244
Updated: 2024-08-02T08:57:35.503Z
Status : Modified
Published: 2024-03-01T21:15:07.613
Modified: 2024-11-21T08:45:35.747
Link: CVE-2023-7244
No data.
OpenCVE Enrichment
No data.
EUVD