Vulnerability Details CVE-2022-43606
A use-of-uninitialized-pointer vulnerability exists in the Forward Open connection_management_entry functionality of EIP Stack Group OpENer development commit 58ee13c. A specially-crafted EtherNet/IP request can lead to use of a null pointer, causing the server to crash. An attacker can send a series of EtherNet/IP requests to trigger this vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 31.9%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2022-43606
-
cpe:2.3:a:opener_project:opener:1.2.0
-
cpe:2.3:a:opener_project:opener:2.1.0
-
cpe:2.3:a:opener_project:opener:2.2.0
-
cpe:2.3:a:opener_project:opener:2.2.1
-
cpe:2.3:a:opener_project:opener:2.3
-
cpe:2.3:a:opener_project:opener:2.3.0