CVE-2024-39589
HIGHDescription
Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a36d95b73e7b8722d0edb8b9c5bb56a. A specially crafted EtherNet/IP request can lead to denial of service. An attacker can send a series of EtherNet/IP requests to trigger these vulnerabilities.This instance of the vulnerability occurs within the `Protected_Logical_Read_Reply` function
Is your site exposed to CVE-2024-39589?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| openplcproject | openplc_v3_firmware |
References
Frequently Asked Questions
What is CVE-2024-39589? +
How severe is CVE-2024-39589? +
What products are affected by CVE-2024-39589? +
How do I check if I'm vulnerable to CVE-2024-39589? +
Related Vulnerabilities
Arcane Software’s Vermillion FTP Daemon (vftpd) versions up to and including 1.31 contains a memory corruption vulnerability triggered by a …
Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. There are various account address types in …
An unauthorized remote attacker can bypass the authentication of the affected software package by misusing an incorrect type conversion. This …
An unauthenticated remote attacker can bypass the login to the web application of the affected devices making it possible to …
Type confusion in Snapchat LensCore could lead to denial of service or arbitrary code execution prior to version 12.88. We …
A type confusion vulnerability exists in the handling of the string addition (+) operation within the QuickJS engine. * The …