"value":"\n\nIndustrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat \nZeek Plugin versions d78dda6 and prior are vulnerable to out-of-bounds \nread during the process of analyzing a specific Ethercat packet. This \ncould allow an attacker to crash the Zeek process and leak some \ninformation in memory.\n\n\n\n\n\n"
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"CWE-125 Out-of-bounds Read",
"cweId":"CWE-125"
}
]
}
]
},
"affects":{
"vendor":{
"vendor_data":[
{
"vendor_name":"CISA",
"product":{
"product_data":[
{
"product_name":"Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Plugin for Zeek",
"value":"\nCISA recommends that users update Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Zeek Plugin to <a target=\"_blank\" rel=\"nofollow\" href=\"https://github.com/cisagov/icsnpp-ethercat\">commit 3bca34c or later</a><span style=\"background-color: var(--wht);\">.</span><p>To help reduce successful exploitation, users are encouraged to keep \ncritical software updates and patches up to date in their system \nnetworks.</p>\n\n<br>"
}
],
"value":"CISA recommends that users update Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Zeek Plugin to commit 3bca34c or later https://github.com/cisagov/icsnpp-ethercat .To help reduce successful exploitation, users are encouraged to keep \ncritical software updates and patches up to date in their system \nnetworks.\n\n\n\n\n"
}
],
"credits":[
{
"lang":"en",
"value":"Cameron Whitehead of HACK@UCF reported these vulnerabilities to CISA."