PT-2017-11984 · Belden Hirschmann · Tofino Xenon Security Appliance

Julien Lenoir

·

Published

2017-11-20

·

Updated

2022-04-04

·

CVE-2017-11401

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Belden Hirschmann Tofino Xenon Security Appliance versions prior to 03.2.00
Description An issue has been discovered that allows an attacker to bypass function code filtering by sending malformed or crafted ModBus packets to a protected asset. This is due to improper handling of the mbap.length field of ModBus packets in the ModBus DPI filter.
Recommendations For versions prior to 03.2.00, update to version 03.2.00 or later to resolve the issue. As a temporary workaround, consider restricting access to the ModBus DPI filter until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-11401

Affected Products

Tofino Xenon Security Appliance