ZeroHour

CVE-2017-6023

CVSS 3.1
9.8 critical
EPSS
4%p91
Published
()
Modified
Description

An issue was discovered in Fatek Automation PLC Ethernet Module. The affected Ether_cfg software configuration tool runs on the following Fatek PLCs: CBEH versions prior to V3.6 Build 170215, CBE versions prior to V3.6 Build 170215, CM55E versions prior to V3.6 Build 170215, and CM25E versions prior to V3.6 Build 170215. A stack-based buffer overflow vulnerability has been identified, which may allow remote code execution or crash the affected device.

Vendors
fatek
Products
ethernet module configuration tool cbe firmware, ethernet module configuration tool cbeh firmware, ethernet module configuration tool cm25e firmware, ethernet module configuration tool cm55e firmware
Weakness
CWE-121, CWE-119
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.