Pyramid EtherNet/IP Adapter Development Kit denial of service | CVE-2022-1737
NAME
Pyramid EtherNet/IP Adapter Development Kit denial of service
- Platforms Affected:
Pyramid Solutions EtherNet/IP Adapter Development Kit 4.4
Pyramid Solutions EtherNet/IP Adapter DLL Kit 4.4
Pyramid Solutions EtherNet/IP Scanner Development Kit 4.4
Pyramid Solutions erNet/IP Scanner DLL Kit 4.4 - Risk Level:
9.8 - Exploitability:
Unproven - Consequences:
Denial of Service
DESCRIPTION
Pyramid EtherNet/IP Adapter Development Kit is vulnerable to a denial of service, caused by an out-of-bounds write flaw. By sending a specially crafted packet, an remote attacker could exploit this vulnerability to cause the application to crash.
CVSS 3.0 Information
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Access Vector: Network
- Access Complexity: Low
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
- Remediation Level: Official Fix
MITIGATION
Upgrade to the latest version of EtherNet/IP Adapter Products (4.4.1 or later), available from the Pyramid Solutions website. See References.
- Reference Link:
https://www.cisa.gov/uscert/ics/advisories/icsa-22-174-04 - Reference Link:
https://pyramidsolutions.com/products/netstax/
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.