ENIP Stack Vulnerability Causes Crashes or Leads to Code Execution
ID: e1079b8a-ac59-5814-a579-d71487f7c3b4
STIX ID: report--e1079b8a-ac59-5814-a579-d71487f7c3b4
Feed Name: Claroty Team82
Threat Score
### Executive Summary Claroty disclosed a critical stack-based buffer overflow in RTA's 499ES EtherNet/IP stack (pre-2.28) — CVE-2020-25159 — that can cause DoS or enable remote code execution via a crafted forward-open CIP path; ICS-CERT rated it CVSS 9.8 and Claroty's fingerprinting tool identified multiple likely-affected devices across vendors, prompting vendor notifications and recommendations to update affected stacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
