Vulnerability Details CVE-2017-6023
An issue was discovered in Fatek Automation PLC Ethernet Module. The affected Ether_cfg software configuration tool runs on the following Fatek PLCs: CBEH versions prior to V3.6 Build 170215, CBE versions prior to V3.6 Build 170215, CM55E versions prior to V3.6 Build 170215, and CM25E versions prior to V3.6 Build 170215. A stack-based buffer overflow vulnerability has been identified, which may allow remote code execution or crash the affected device.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.032
EPSS Ranking 86.4%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 9.0
Products affected by CVE-2017-6023
-
cpe:2.3:h:fatek:plc_ethernet_module:-
-
cpe:2.3:o:fatek:ethernet_module_configuration_tool_cbe_firmware:3.5
-
cpe:2.3:o:fatek:ethernet_module_configuration_tool_cbeh_firmware:3.5
-
cpe:2.3:o:fatek:ethernet_module_configuration_tool_cm25e_firmware:3.5
-
cpe:2.3:o:fatek:ethernet_module_configuration_tool_cm55e_firmware:3.5