CVE-2024-39589: Incorrect Type Cast
Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLCv3 16bf8bac1a36d95b73e7b8722d0edb8b9c5bb56a. A specially crafted EtherNet/IP request can lead to denial of service. An attacker can send a series of EtherNet/IP requests to trigger these vulnerabilities.This instance of the vulnerability occurs within the ProtectedLogicalReadReply function
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39589?
CVE-2024-39589 has a severity rating that indicates it can lead to denial of service due to multiple invalid pointer dereference vulnerabilities.
How do I fix CVE-2024-39589?
To fix CVE-2024-39589, update to the latest version of OpenPLC_v3 firmware released after May 28, 2024.
What type of vulnerability is CVE-2024-39589?
CVE-2024-39589 is classified as an invalid pointer dereference vulnerability related to the EtherNet/IP parser in OpenPLC Runtime.
Which version of OpenPLC_v3 is affected by CVE-2024-39589?
CVE-2024-39589 affects OpenPLC_v3 firmware version 2024-05-28.
Can CVE-2024-39589 be exploited remotely?
Yes, CVE-2024-39589 can be exploited remotely by sending specially crafted EtherNet/IP requests.