PT-2025-54109 · Snap7-Rs · Snap7-Rs
Gmg137
·
Published
2025-12-30
·
Updated
2026-01-12
·
CVE-2025-15247
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
snap7-rs versions prior to 153d3e8c16decd7271e2a5b2e3da4d6f68589424
Description
A flaw exists in snap7-rs that could lead to a heap-based buffer overflow. The issue is located in the
snap7 rs::client::S7Client::download function within the client.rs file. This manipulation can be triggered remotely. The exploit is publicly available.Recommendations
Update snap7-rs to a version prior to 153d3e8c16decd7271e2a5b2e3da4d6f68589424.
As a temporary workaround, consider restricting the use of the
snap7 rs::client::S7Client::download function until a patch is available.Exploit
Fix
Heap Based Buffer Overflow
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Snap7-Rs