CVE-2024-36980
An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f71b4543298d77007b88. A specially crafted network request can lead to denial of service. An attacker can send a series of EtherNet/IP requests to trigger this vulnerability.This is the first instance of the incorrect comparison.
Published:Sep 18, 2024
Last Modified:Nov 4, 2025
EPS:Sep 18, 2024
EPSS Score:0.00301
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Openplcproject
Product
Openplc V3
Openplcproject
Openplc V3
Vendor
Openplcproject
Product
Openplc V3 Firmware
Openplcproject
Openplc V3 Firmware
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
