A stack-based buffer overflow vulnerability exists in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC _v3 b4702061dc14d1024856f71b4543298d77007b88. A specially crafted EtherNet/IP request can lead to remote code execution. An attacker can send a series of EtherNet/IP requests to trigger this vulnerability.
The vulnerability results from a stack-based buffer overflow (CWE-121, CWE-787) in the component responsible for parsing the EtherNet/IP protocol in OpenPLC Runtime. An attacker sends a series of specially crafted EtherNet/IP requests that cause data to be written beyond the boundaries of the allocated stack buffer. This leads to corruption of the process memory and consequently to arbitrary code execution on the vulnerable device. The attack is possible remotely without the need to possess any access credentials.
Successful exploitation of the vulnerability enables an attacker to execute code remotely (RCE) with the privilege level of the OpenPLC Runtime process, which can lead to complete system takeover, breach of data confidentiality and integrity, and disruption of the availability of the controlled industrial process.
Patches available from the manufacturer should be applied according to the references. Additionally, it is recommended to restrict network access to the EtherNet/IP interface only to trusted hosts using a firewall and to segment the OT/ICS network by separating PLC controllers from corporate networks and the Internet.
OpenPLC V3 Runtime — specifically commit b4702061dc14d1024856f71b4543298d77007b88 of the Openplcproject project
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HOpenplcproject Openplc V3 Firmware
OSOpenplcproject2024-04-04
Related vulnerabilities
OpenPLC V3 — pominięcie uwierzytelnienia przez niezabezpieczoną domyślną inicjalizację
OpenPLC V3 — przechowywanie haseł w postaci jawnego tekstu (CWE-256)
Buffer overflow w OpenPLC V2/V3 — funkcja mapUnusedIO() w modbus.cpp
OpenPLC_V3 REST API endpoint checks for JWT presence but never verifies the caller's role. Any authenticated u...
An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of Ope...