Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat
Zeek Plugin versions d78dda6 and prior are vulnerable to out-of-bounds
write in their primary analyses function for Ethercat communication
packets. This could allow an attacker to cause arbitrary code execution.

Fixes

Solution

CISA recommends that users update Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Zeek Plugin to commit 3bca34c or later https://github.com/cisagov/icsnpp-ethercat .To help reduce successful exploitation, users are encouraged to keep critical software updates and patches up to date in their system networks.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-08-05T13:13:35.428Z

Reserved: 2024-02-01T17:21:33.223Z

Link: CVE-2023-7244

cve-icon Vulnrichment

Updated: 2024-08-02T08:57:35.503Z

cve-icon NVD

Status : Modified

Published: 2024-03-01T21:15:07.613

Modified: 2024-11-21T08:45:35.747

Link: CVE-2023-7244

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.