CVE-2024-34026: Buffer Overflow
A stack-based buffer overflow vulnerability exists in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC v3 b4702061dc14d1024856f71b4543298d77007b88. A specially crafted EtherNet/IP request can lead to remote code execution. An attacker can send a series of EtherNet/IP requests to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34026?
CVE-2024-34026 has been rated as a critical severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2024-34026?
To mitigate CVE-2024-34026, it is recommended to upgrade OpenPLC to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2024-34026?
CVE-2024-34026 is a stack-based buffer overflow vulnerability specifically affecting the EtherNet/IP parser in OpenPLC.
Who is affected by CVE-2024-34026?
CVE-2024-34026 affects users of OpenPLC version 2024-04-04 and earlier versions utilizing the EtherNet/IP functionality.
What are the potential consequences of exploiting CVE-2024-34026?
Exploiting CVE-2024-34026 could lead to remote code execution, allowing attackers to compromise the affected system.