Security Advisory

CVE-2022-43606

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-03-16 20:02:09
Last updated 2024-08-03 13:32:59
Assigner talos
CVSS score 7.5
State PUBLISHED

Description

A use-of-uninitialized-pointer vulnerability exists in the Forward Open connection_management_entry functionality of EIP Stack Group OpENer development commit 58ee13c. A specially-crafted EtherNet/IP request can lead to use of a null pointer, causing the server to crash. An attacker can send a series of EtherNet/IP requests to trigger this vulnerability.