PT-2021-23744 · Apache · Apache Plc4X

Eugene Lim

·

Published

2021-12-19

·

Updated

2022-01-04

·

CVE-2021-43083

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache PLC4X - PLC4C versions prior to 0.9.1
Description The issue is related to an unsigned integer underflow flaw inside the tcp transport. To exploit this, a user would have to actively connect to a malicious device that could send a response with invalid content. The probability of this being exploited is currently considered minimal, but this could change in the future, especially with industrial networks growing together.
Recommendations For versions prior to 0.9.1, update to version 0.9.1 to address the issue. As a temporary workaround, consider restricting connections to trusted devices to minimize the risk of exploitation.

Fix

Integer Underflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-43083

Affected Products

Apache Plc4X