Ethercat Vulnerable to Out-of-Bounds Write Attack
CVE-2023-7244

9.8CRITICAL

What is CVE-2023-7244?

The vulnerability affects Industrial Control Systems Network Protocol Parsers (ICSNPP) specifically for Ethercat communication packets. In versions of the Zeek Plugin up to and including d78dda6, there is a potential for an out-of-bounds write during the primary analysis function. This security flaw can be exploited by an attacker to execute arbitrary code, possibly allowing unauthorized access and manipulation of the system. It highlights the importance of applying library updates and maintaining security practices to safeguard industrial control environments.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Plugin for Zeek 0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Cameron Whitehead of HACK@UCF reported these vulnerabilities to CISA.
.