The 17046 Ethernet card before 94450214LFMT100SEM-L.R3-CL for the GE Digital Energy Hydran M2 does not properly generate random values for TCP Initial Sequence Numbers (ISNs), which makes it easier for remote attackers to spoof packets by predicting these values.
oryginał ENCVSS Vector
AV:N/AC:L/Au:N/C:P/I:N/A:PGe Hydran M2
HWGewszystkie wersje
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Powiązane podatności
CVE-2023-5908CRITICAL9.1PL ✓ten sam vendor
Buffer overflow w KEPServerEX umożliwiający crash lub wyciek danych
CVE-2022-2848CRITICAL9.1PL ✓ten sam vendor
Zdalne wykonanie kodu w Kepware KEPServerEX – heap buffer overflow
CVE-2022-2825CRITICAL9.8PL ✓ten sam vendor
RCE bez uwierzytelnienia w Kepware KEPServerEX — stack-based buffer overflow
CVE-2023-0754CRITICAL9.8PL ✓ten sam vendor
Integer overflow umożliwiający RCE w produktach GE Digital i PTC Kepware
CVE-2023-0755CRITICAL9.8PL ✓ten sam vendor
Nieprawidłowa walidacja indeksu tablicy w produktach GE/PTC — RCE