CVE Published: 01/03/2024 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: icscert |
Vendor: CISA |
Product: Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Plugin for Zeek Status : PUBLISHED
CVE-2023-7242 Description
Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat
Zeek Plugin versions d78dda6 and prior are vulnerable to out-of-bounds
read during the process of analyzing a specific Ethercat packet. This
could allow an attacker to crash the Zeek process and leak some
information in memory.
Metrics
CVSS Version: 3.1 |
Base Score: 8.2 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H