PT-2017-11984 · Belden Hirschmann · Tofino Xenon Security Appliance
Julien Lenoir
·
Publicado
2017-11-20
·
Atualizado
2022-04-04
·
CVE-2017-11401
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Belden Hirschmann Tofino Xenon Security Appliance versions prior to 03.2.00
Description
An issue has been discovered that allows an attacker to bypass function code filtering by sending malformed or crafted ModBus packets to a protected asset. This is due to improper handling of the
mbap.length field of ModBus packets in the ModBus DPI filter.Recommendations
For versions prior to 03.2.00, update to version 03.2.00 or later to resolve the issue. As a temporary workaround, consider restricting access to the ModBus DPI filter until a patch is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Tofino Xenon Security Appliance