PT-2022-20395 · Unknown · En100 Ethernet Module Profinet Io Variant+4

Published

2022-06-14

·

Updated

2023-06-29

·

CVE-2022-30937

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions EN100 Ethernet module DNP3 IP variant (All versions) EN100 Ethernet module IEC 104 variant (All versions) EN100 Ethernet module IEC 61850 variant (All versions prior to V4.37) EN100 Ethernet module Modbus TCP variant (All versions) EN100 Ethernet module PROFINET IO variant (All versions)
Description A memory corruption issue exists while parsing specially crafted HTTP packets to the "/txtrace" endpoint. This could allow an attacker to crash the affected application, leading to a denial of service condition.
Recommendations For EN100 Ethernet module DNP3 IP variant, restrict access to the "/txtrace" endpoint until a patch is available. For EN100 Ethernet module IEC 104 variant, consider disabling the HTTP parsing functionality for the "/txtrace" endpoint as a temporary workaround. For EN100 Ethernet module IEC 61850 variant, update to version V4.37 or later to resolve the issue. For EN100 Ethernet module Modbus TCP variant, avoid using the "/txtrace" endpoint until the issue is resolved. For EN100 Ethernet module PROFINET IO variant, restrict access to the "/txtrace" endpoint to minimize the risk of exploitation.

Fix

Memory Corruption

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-30937

Affected Products

En100 Ethernet Module Dnp3 Variant
En100 Ethernet Module Iec104 Variant
En100 Ethernet Module Iec 61850 Variant
En100 Ethernet Module Modbus Tcp Variant
En100 Ethernet Module Profinet Io Variant