CVE-2024-39590: Incorrect Type Cast
Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLCv3 16bf8bac1a36d95b73e7b8722d0edb8b9c5bb56a. A specially crafted EtherNet/IP request can lead to denial of service. An attacker can send a series of EtherNet/IP requests to trigger these vulnerabilities.This instance of the vulnerability occurs within the ProtectedLogicalWriteReply function
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39590?
CVE-2024-39590 is classified as a denial of service vulnerability due to its potential to impact system availability.
How can I fix CVE-2024-39590?
To mitigate CVE-2024-39590, users should update to the latest version of the OpenPLC v3 firmware.
What causes CVE-2024-39590?
CVE-2024-39590 is caused by multiple invalid pointer dereference vulnerabilities in the EtherNet/IP parser functionality.
Who is affected by CVE-2024-39590?
CVE-2024-39590 affects users running OpenPLC v3 firmware version 2024-05-28 or earlier.
What are the potential impacts of CVE-2024-39590?
The potential impacts of CVE-2024-39590 include denial of service, leading to disruptions in service availability.