CVE-2023-7242: Ethercat Zeek Plugin Out-of-bounds Read
Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Zeek Plugin versions d78dda6 and prior are vulnerable to out-of-bounds read during the process of analyzing a specific Ethercat packet. This could allow an attacker to crash the Zeek process and leak some information in memory.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7242?
CVE-2023-7242 is classified as a moderate vulnerability due to its potential to crash the Zeek process and cause disruptions in ICS networks.
How do I fix CVE-2023-7242?
To mitigate CVE-2023-7242, upgrade to Zeek plugin versions newer than d78dda6 that have addressed this vulnerability.
What type of vulnerability is CVE-2023-7242?
CVE-2023-7242 is an out-of-bounds read vulnerability affecting the Ethercat parser in the ICSNPP Zeek plugin.
What could be the potential impact of CVE-2023-7242?
The potential impact of CVE-2023-7242 includes crashing the Zeek process and possibly leaking information from the ICS network.
Which software versions are affected by CVE-2023-7242?
CVE-2023-7242 affects the ICSNPP Ethercat Zeek plugin versions d78dda6 and earlier.