PT-2024-37419 · Robotware · Robotware
Published
2024-10-10
·
Updated
2024-10-15
·
CVE-2024-6157
CVSS v3.1
5.1
Medium
| Vector | AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
RobotWare versions prior to 6.15.06, except versions 6.10.10 and 6.13.07
Description:
A vulnerability exists in the PROFINET stack included in RobotWare. This issue arises under specific conditions when a specially crafted message is processed by the system. An attacker who successfully exploits this vulnerability could cause the robot to stop.
Recommendations:
For versions prior to 6.15.06, except 6.10.10 and 6.13.07, update to version 6.15.06 or later to resolve the issue.
For versions 6.10.10 and 6.13.07, no specific action is required as these versions are not affected by this vulnerability.
As a temporary workaround, consider restricting access to the PROFINET stack until a patch is available.
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Robotware