CVE-2017-11401

CRITICAL

Belden Hirschmann Tofino Xenon Security Appliance <03.2.00 - ModBus DPI Filter Bypass

Title source: llm
STIX 2.1

Description

An issue has been discovered on the Belden Hirschmann Tofino Xenon Security Appliance before 03.2.00. Improper handling of the mbap.length field of ModBus packets in the ModBus DPI filter allows an attacker to send malformed/crafted packets to a protected asset, bypassing function code filtering.

Scores

CVSS v3 9.8
EPSS 0.0008
EPSS Percentile 23.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (1)
belden/tofino_xenon_security_appliance_firmware < 3.1.0
Published Nov 20, 2017
Tracked Since Feb 18, 2026