cbcvebase.

Opener Project Opener vulnerabilities

11 known vulnerabilities affecting opener_project/opener.

Total CVEs
11
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH7

Vulnerabilities

Page 1 of 1
CVE-2022-43604P2CRITICALCVSS 9.8fixed in 2022-10-182023-03-16
CVE-2022-43604 [CRITICAL] CWE-787 CVE-2022-43604: An out-of-bounds write vulnerability exists in the GetAttributeList attribute_count_request function An out-of-bounds write vulnerability exists in the GetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. A specially crafted EtherNet/IP request can lead to an out-of-bounds write, potentially causing the server to crash or allow for remote code execution. An attacker can send a series of Ethe
nvd
CVE-2022-43605P2CRITICALCVSS 9.8fixed in 2022-10-182023-03-16
CVE-2022-43605 [CRITICAL] CWE-787 CVE-2022-43605: An out-of-bounds write vulnerability exists in the SetAttributeList attribute_count_request function An out-of-bounds write vulnerability exists in the SetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. A specially crafted EtherNet/IP request can lead to an out of bounds write, potentially causing the server to crash or allow for remote code execution. An attacker can send a series of Ethe
nvd
CVE-2020-13556P2CRITICALCVSS 9.8v2.32020-12-11
CVE-2020-13556 [CRITICAL] CWE-787 CVE-2020-13556: An out-of-bounds write vulnerability exists in the Ethernet/IP server functionality of EIP Stack Gro An out-of-bounds write vulnerability exists in the Ethernet/IP server functionality of EIP Stack Group OpENer 2.3 and development commit 8c73bf3. A specially crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.
nvd
CVE-2021-21777P3CRITICALCVSS 10.0v2.32021-06-17
CVE-2021-21777 [CRITICAL] CWE-125 CVE-2021-21777: An information disclosure vulnerability exists in the Ethernet/IP UDP handler functionality of EIP S An information disclosure vulnerability exists in the Ethernet/IP UDP handler functionality of EIP Stack Group OpENer 2.3 and development commit 8c73bf3. A specially crafted network request can lead to an out-of-bounds read.
nvd
CVE-2022-43606P3HIGHCVSS 7.5fixed in 2022-10-182023-03-16
CVE-2022-43606 [HIGH] CWE-824 CVE-2022-43606: A use-of-uninitialized-pointer vulnerability exists in the Forward Open connection_management_entry A use-of-uninitialized-pointer vulnerability exists in the Forward Open connection_management_entry functionality of EIP Stack Group OpENer development commit 58ee13c. A specially-crafted EtherNet/IP request can lead to use of a null pointer, causing the server to crash. An attacker can send a series of EtherNet/IP requests to trigger this vulnerabilit
nvd
CVE-2021-27482P3HIGHCVSS 7.5≤ 2.32022-05-12
CVE-2021-27482 [HIGH] CWE-125 CVE-2021-27482: A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and ve A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may allow the attacker to read arbitrary data.
nvd
CVE-2020-13530P3HIGHCVSS 7.5v2.32020-12-11
CVE-2020-13530 [HIGH] CWE-910 CVE-2020-13530: A denial-of-service vulnerability exists in the Ethernet/IP server functionality of the EIP Stack Gr A denial-of-service vulnerability exists in the Ethernet/IP server functionality of the EIP Stack Group OpENer 2.3 and development commit 8c73bf3. A large number of network requests in a small span of time can cause the running program to stop. An attacker can send a sequence of requests to trigger this vulnerability.
nvd
CVE-2021-27500P3HIGHCVSS 7.5≤ 2.32022-05-12
CVE-2021-27500 [HIGH] CWE-617 CVE-2021-27500: A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and ve A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may result in a denial-of-service condition.
nvd
CVE-2021-27498P3HIGHCVSS 7.5≤ 2.32022-05-12
CVE-2021-27498 [HIGH] CWE-617 CVE-2021-27498: A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and ve A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may result in a denial-of-service condition.
nvd
CVE-2021-27478P3HIGHCVSS 7.5≤ 2.32022-05-12
CVE-2021-27478 [HIGH] CWE-681 CVE-2021-27478: A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and ve A specifically crafted packet sent by an attacker to EIPStackGroup OpENer EtherNet/IP commits and versions prior to Feb 10, 2021 may cause a denial-of-service condition.
nvd
CVE-2022-32434P3HIGHCVSS 7.8v2.3.02022-07-15
CVE-2022-32434 [HIGH] CWE-787 CVE-2022-32434: EIPStackGroup OpENer v2.3.0 was discovered to contain a stack overflow via /bin/posix/src/ports/POSI EIPStackGroup OpENer v2.3.0 was discovered to contain a stack overflow via /bin/posix/src/ports/POSIX/OpENer+0x56073d.
nvd
Opener Project Opener vulnerabilities | cvebase