Vulnerability Description
An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f71b4543298d77007b88. A specially crafted network request can lead to denial of service. An attacker can send a series of EtherNet/IP requests to trigger this vulnerability.This is the first instance of the incorrect comparison.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openplcproject | Openplc V3 Firmware | 2024-04-04 |
Related Weaknesses (CWE)
References
- https://talosintelligence.com/vulnerability_reports/TALOS-2024-2004ExploitThird Party Advisory
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2004
FAQ
What is CVE-2024-36980?
CVE-2024-36980 is a vulnerability with a CVSS score of 7.5 (HIGH). An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f71b4543298d77007b88. A specially crafted network request can ...
How severe is CVE-2024-36980?
CVE-2024-36980 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-36980?
Check the references section above for vendor advisories and patch information. Affected products include: Openplcproject Openplc V3 Firmware.