CVE-2024-34026

CRITICAL

OpenPLC v3 b4702061dc14d1024856f71b4543298d77007b88 - Stack-based Buffer Overflow in EtherNet/IP Parser

Title source: llm
STIX 2.1

Description

A stack-based buffer overflow vulnerability exists in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC _v3 b4702061dc14d1024856f71b4543298d77007b88. A specially crafted EtherNet/IP request can lead to remote code execution. An attacker can send a series of EtherNet/IP requests to trigger this vulnerability.

References (2)

Core 2

Scores

CVSS v3 9.0
EPSS 0.0241
EPSS Percentile 82.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-121 CWE-787
Status published
Products (1)
openplcproject/openplc_v3_firmware 2024-04-04
Published Sep 18, 2024
Tracked Since Feb 18, 2026