CVE Feed

    Dashboard / CVE / CVE-2021-43083

    CVE-2021-43083

    Apache PLC4X - PLC4C (Only the C language implementation was effected) was vulnerable to an unsigned integer underflow flaw inside the tcp transport. Users should update to 0.9.1, which addresses this issue. However, in order to exploit this vulnerability, a user would have to actively connect to a mallicious device which could send a response with invalid content. Currently we consider the probability of this being exploited as quite minimal, however this could change in the future, especially with the industrial networks growing more and more together.

    Published:Dec 19, 2021
    Last Modified:Nov 21, 2024
    EPS:Dec 19, 2021
    EPSS Score:0.02393
    CVSS Score:8.8

    Affected Products

    Vendor
    Apache
    Product
    Plc4x

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High