CRITICAL🇵🇱 Wersja polska

CVE-2024-34026

CVSS 9.0v3.1pub. 2024-09-18upd. 2024-11-21

A stack-based buffer overflow vulnerability exists in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC _v3 b4702061dc14d1024856f71b4543298d77007b88. A specially crafted EtherNet/IP request can lead to remote code execution. An attacker can send a series of EtherNet/IP requests to trigger this vulnerability.

🤖 AI Analysis
How it works

The vulnerability results from a stack-based buffer overflow (CWE-121, CWE-787) in the component responsible for parsing the EtherNet/IP protocol in OpenPLC Runtime. An attacker sends a series of specially crafted EtherNet/IP requests that cause data to be written beyond the boundaries of the allocated stack buffer. This leads to corruption of the process memory and consequently to arbitrary code execution on the vulnerable device. The attack is possible remotely without the need to possess any access credentials.

Impact

Successful exploitation of the vulnerability enables an attacker to execute code remotely (RCE) with the privilege level of the OpenPLC Runtime process, which can lead to complete system takeover, breach of data confidentiality and integrity, and disruption of the availability of the controlled industrial process.

Mitigation & patch

Patches available from the manufacturer should be applied according to the references. Additionally, it is recommended to restrict network access to the EtherNet/IP interface only to trusted hosts using a firewall and to segment the OT/ICS network by separating PLC controllers from corporate networks and the Internet.

Who is affected

OpenPLC V3 Runtime — specifically commit b4702061dc14d1024856f71b4543298d77007b88 of the Openplcproject project

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Openplcproject Openplc V3 Firmware

    OS
    Openplcproject
    2024-04-04
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEMemory
CWE
References

Related vulnerabilities

CVE-2026-28205CRITICAL9.2PL ✓same product

OpenPLC V3 — pominięcie uwierzytelnienia przez niezabezpieczoną domyślną inicjalizację

CVE-2026-35556CRITICAL9.2PL ✓same product

OpenPLC V3 — przechowywanie haseł w postaci jawnego tekstu (CWE-256)

CVE-2018-20818CRITICAL9.8PL ✓same product

Buffer overflow w OpenPLC V2/V3 — funkcja mapUnusedIO() w modbus.cpp

CVE-2026-35063HIGH8.7same product

OpenPLC_V3 REST API endpoint checks for JWT presence but never verifies the caller's role. Any authenticated u...

CVE-2024-36980HIGH7.5same product

An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of Ope...