PT-2024-37419 · Robotware · Robotware

Published

2024-10-10

·

Updated

2024-10-15

·

CVE-2024-6157

CVSS v3.1

5.1

Medium

VectorAV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: RobotWare versions prior to 6.15.06, except versions 6.10.10 and 6.13.07
Description: A vulnerability exists in the PROFINET stack included in RobotWare. This issue arises under specific conditions when a specially crafted message is processed by the system. An attacker who successfully exploits this vulnerability could cause the robot to stop.
Recommendations: For versions prior to 6.15.06, except 6.10.10 and 6.13.07, update to version 6.15.06 or later to resolve the issue. For versions 6.10.10 and 6.13.07, no specific action is required as these versions are not affected by this vulnerability. As a temporary workaround, consider restricting access to the PROFINET stack until a patch is available.

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2024-6157

Affected Products

Robotware