CVE-2023-7244

Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Zeek Plugin versions d78dda6 and prior are vulnerable to out-of-bounds write in their primary analyses function for Ethercat communication packets. This could allow an attacker to cause arbitrary code execution.
References
Link Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-24-051-02 US Government Resource Vendor Advisory
https://www.cisa.gov/news-events/ics-advisories/icsa-24-051-02 US Government Resource Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:cisa:icsnpp-ethercat:*:*:*:*:*:zeek:*:*

History

21 Nov 2024, 08:45

Type Values Removed Values Added
References () https://www.cisa.gov/news-events/ics-advisories/icsa-24-051-02 - US Government Resource, Vendor Advisory () https://www.cisa.gov/news-events/ics-advisories/icsa-24-051-02 - US Government Resource, Vendor Advisory

07 Mar 2024, 17:51

Type Values Removed Values Added
Summary
  • (es) Industrial Control Systems Network Protocol Parsers (ICSNPP): las versiones d78dda6 y anteriores del complemento Ethercat Zeek son vulnerables a escritura fuera de los límites en su función de análisis principal para paquetes de comunicación Ethercat. Esto podría permitir que un atacante provoque la ejecución de código arbitrario.
References () https://www.cisa.gov/news-events/ics-advisories/icsa-24-051-02 - () https://www.cisa.gov/news-events/ics-advisories/icsa-24-051-02 - US Government Resource, Vendor Advisory
First Time Cisa
Cisa icsnpp-ethercat
CPE cpe:2.3:a:cisa:icsnpp-ethercat:*:*:*:*:*:zeek:*:*

01 Mar 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-01 21:15

Updated : 2024-11-21 08:45


NVD link : CVE-2023-7244

Mitre link : CVE-2023-7244

CVE.ORG link : CVE-2023-7244


JSON object : View

Products Affected

cisa

  • icsnpp-ethercat
CWE
CWE-787

Out-of-bounds Write