CVE-2022-43606: High severity opener project opener vulnerability
A use-of-uninitialized-pointer vulnerability exists in the Forward Open connectionmanagemententry functionality of EIP Stack Group OpENer development commit 58ee13c. A specially-crafted EtherNet/IP request can lead to use of a null pointer, causing the server to crash. An attacker can send a series of EtherNet/IP requests to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID is CVE-2022-43606.
What is the severity of CVE-2022-43606?
The severity of CVE-2022-43606 is high with a severity value of 7.5.
What software is affected by CVE-2022-43606?
The Opener Project Opener software versions up until October 18, 2022, are affected by CVE-2022-43606.
What is the CWE ID associated with CVE-2022-43606?
The CWE ID associated with CVE-2022-43606 is CWE-824.
How can this vulnerability be exploited?
An attacker can exploit this vulnerability by sending a specially-crafted EtherNet/IP request, leading to the use of a null pointer and causing the server to crash.