Multiple Invalid Pointer Dereference Issues in OpenPLC Runtime by OpenPLC
CVE-2024-39590
7.5HIGH
What is CVE-2024-39590?
Multiple vulnerabilities related to invalid pointer dereferences have been identified in the EtherNet/IP parser functionality of OpenPLC Runtime, specifically within the Protected_Logical_Write_Reply
function. These vulnerabilities allow an attacker to send specially crafted EtherNet/IP requests, which can trigger a denial of service condition. This can disrupt the normal operation of the affected products, making it crucial for users to implement appropriate security measures to mitigate these risks.