CVE-2023-3242: Race Condition
Allocation of Resources Without Limits or Throttling, Improper Initialization vulnerability in B&R Industrial Automation B&R Automation Runtime allows Flooding, Leveraging Race Conditions.This issue affects B&R Automation Runtime: <G4.93.
Other sources
Improper initialization implementation in Portmapper used in B&R Industrial Automation Automation Runtime <G4.93 allows unauthenticated network-based attackers to cause permanent denial-of-service conditions.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3242?
CVE-2023-3242 is considered a high severity vulnerability due to its potential for flooding and exploiting race conditions.
How do I fix CVE-2023-3242?
To fix CVE-2023-3242, you should update B&R Automation Runtime to a version beyond G4.93 that addresses the improper initialization issue.
What type of systems does CVE-2023-3242 affect?
CVE-2023-3242 affects systems running B&R Automation Runtime version up to G4.93.
What is the main issue with CVE-2023-3242?
The main issue with CVE-2023-3242 is the improper initialization in the Portmapper, leading to potential resource flooding.
Can CVE-2023-3242 be exploited remotely?
Yes, CVE-2023-3242 can potentially be exploited remotely due to its nature related to resource allocation without proper limits.