logo

ENIP Stack Vulnerability Causes Crashes or Leads to Code Execution

ID: e1079b8a-ac59-5814-a579-d71487f7c3b4

STIX ID: report--e1079b8a-ac59-5814-a579-d71487f7c3b4

Feed Name: Claroty Team82

Threat Score
75/100

Date Published: 2023-09-20

Date Updated: 2026-04-17

Author: Sharon Brizinov

...
...

### Executive Summary Claroty disclosed a critical stack-based buffer overflow in RTA's 499ES EtherNet/IP stack (pre-2.28) — CVE-2020-25159 — that can cause DoS or enable remote code execution via a crafted forward-open CIP path; ICS-CERT rated it CVSS 9.8 and Claroty's fingerprinting tool identified multiple likely-affected devices across vendors, prompting vendor notifications and recommendations to update affected stacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.