This content is restricted.
Brief
Summary:
A Critical Vulnerability in Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Plugin for Zeek has been identified, with a CVSS score of 9.8. The vulnerability allows for remote code execution and is exploitable remotely with low attack complexity. The affected software versions are d78dda6 and prior. The vulnerability is due to out-of-bounds write and read issues in the primary analysis function and while analyzing Ethercat packets. CISA recommends updating to commit 3bca34c or later and implementing defensive measures to minimize the risk of exploitation. No known public exploitation has been reported at this time.
Highlights content goes here...
This content is restricted.