← Back to browse · API

CVE-2022-43604

Severity
CRITICAL
CVSS
10.0
EPSS
0.14372
Risk score
45.03
CISA KEV
No
PoC
No
Published
2023-03-16
Modified
2025-03-05
First seen
2026-08-07
Aliases
EUVD-2022-46600, GHSA-6FR5-2XJV-GR58
Products
EIP Stack Group:OpENer development commit 58ee13c
Sources
euvd EUVD-2022-46600

Description

An out-of-bounds write vulnerability exists in the GetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. A specially crafted EtherNet/IP request can lead to an out-of-bounds write, potentially causing the server to crash or allow for remote code execution. An attacker can send a series of EtherNet/IP requests to trigger this vulnerability.

References