CVE-2023-7244: Ethercat Zeek Plugin Out-of-bounds Write
Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Zeek Plugin versions d78dda6 and prior are vulnerable to out-of-bounds write in their primary analyses function for Ethercat communication packets. This could allow an attacker to cause arbitrary code execution.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7244?
CVE-2023-7244 has a critical severity level due to its potential for arbitrary code execution.
How do I fix CVE-2023-7244?
To remediate CVE-2023-7244, update to a version of the CISA Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat plugin newer than d78dda6.
What components are affected by CVE-2023-7244?
CVE-2023-7244 affects CISA Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat versions up to and including d78dda6.
What type of vulnerability is CVE-2023-7244?
CVE-2023-7244 is an out-of-bounds write vulnerability affecting the Ethercat communication packet analyses.
Who is responsible for addressing CVE-2023-7244?
Users of the affected CISA Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat software are responsible for applying the necessary updates to mitigate CVE-2023-7244.