Ethercat Vulnerable to Out-of-Bounds Write Attack
CVE-2023-7244
9.8CRITICAL
What is CVE-2023-7244?
The vulnerability affects Industrial Control Systems Network Protocol Parsers (ICSNPP) specifically for Ethercat communication packets. In versions of the Zeek Plugin up to and including d78dda6, there is a potential for an out-of-bounds write during the primary analysis function. This security flaw can be exploited by an attacker to execute arbitrary code, possibly allowing unauthorized access and manipulation of the system. It highlights the importance of applying library updates and maintaining security practices to safeguard industrial control environments.
Affected Version(s)
Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Plugin for Zeek 0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Cameron Whitehead of HACK@UCF reported these vulnerabilities to CISA.
