Vulnerability CVE-2024-39590


Published: 2024-09-18

Description:
Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a36d95b73e7b8722d0edb8b9c5bb56a. A specially crafted EtherNet/IP request can lead to denial of service. An attacker can send a series of EtherNet/IP requests to trigger these vulnerabilities.This instance of the vulnerability occurs within the `Protected_Logical_Write_Reply` function

Type:

CWE-704

(Incorrect Type Conversion or Cast)

 References:
https://talosintelligence.com/vulnerability_reports/TALOS-2024-2016

Copyright 2024, cxsecurity.com

 

Back to Top