CVE-2024-36845: Medium severity libmodbus vulnerability
Published May 31, 2024
·Updated
An invalid pointer in the modbusreceive() function of libmodbus v3.1.6 allows attackers to cause a Denial of Service (DoS) via a crafted message sent to the unit-test-server.
Affected Software
2 affected components
libmodbus libmodbus
libmodbus libmodbus=3.1.6
Event History
May 31, 2024
CVE Published
via MITRE·07:16 PM
Data Sourced
via MITRE·07:16 PM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-36845?
CVE-2024-36845 is classified as a high-severity vulnerability due to its potential to cause Denial of Service (DoS).
2
How do I fix CVE-2024-36845?
To mitigate CVE-2024-36845, update to the latest version of libmodbus beyond v3.1.6 where the issue is resolved.
3
What type of vulnerability is CVE-2024-36845?
CVE-2024-36845 is a vulnerability resulting from an invalid pointer in the modbus_receive() function.
4
Which versions of libmodbus are affected by CVE-2024-36845?
CVE-2024-36845 affects libmodbus version v3.1.6 and potentially earlier versions.
5
What impact does CVE-2024-36845 have on systems?
CVE-2024-36845 can allow attackers to send crafted messages that cause a Denial of Service (DoS) to the affected system.