Vulnerability Details CVE-2022-43604
An out-of-bounds write vulnerability exists in the GetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. A specially crafted EtherNet/IP request can lead to an out-of-bounds write, potentially causing the server to crash or allow for remote code execution. An attacker can send a series of EtherNet/IP requests to trigger this vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.028
EPSS Ranking 85.6%
CVSS Severity
CVSS v3 Score 10.0
Products affected by CVE-2022-43604
-
cpe:2.3:a:opener_project:opener:1.2.0
-
cpe:2.3:a:opener_project:opener:2.1.0
-
cpe:2.3:a:opener_project:opener:2.2.0
-
cpe:2.3:a:opener_project:opener:2.2.1
-
cpe:2.3:a:opener_project:opener:2.3
-
cpe:2.3:a:opener_project:opener:2.3.0