Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-30937

A vulnerability has been identified in EN100 Ethernet module DNP3 IP variant (All versions), EN100 Ethernet module IEC 104 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.37), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module PROFINET IO variant (All versions). Affected applications contains a memory corruption vulnerability while parsing specially crafted HTTP packets to /txtrace endpoint. This could allow an attacker to crash the affected application leading to a denial of service condition.

CVE
#vulnerability#dos#pdf

%PDF-1.5 %���� 1 0 obj << /D [2 0 R /XYZ 70.866 771.024 null] >> endobj 3 0 obj << /D [2 0 R /XYZ 70.866 630.026 null] >> endobj 4 0 obj << /D [2 0 R /XYZ 70.866 569.947 null] >> endobj 5 0 obj << /D [2 0 R /XYZ 70.866 253.003 null] >> endobj 6 0 obj << /D [2 0 R /XYZ 70.866 98.278 null] >> endobj 7 0 obj << /D [8 0 R /XYZ 85.039 235.088 null] >> endobj 9 0 obj << /D [10 0 R /XYZ 70.866 576.314 null] >> endobj 11 0 obj << /S /GoTo /D [2 0 R /Fit] >> endobj 2 0 obj << /Contents 12 0 R /Type /Page /Resources 13 0 R /Parent 14 0 R /Annots [15 0 R 16 0 R 17 0 R 18 0 R 19 0 R 20 0 R 21 0 R 22 0 R 23 0 R 24 0 R 25 0 R 26 0 R 27 0 R 28 0 R] /MediaBox [0 0 595.276 841.89] >> endobj 15 0 obj << /A << /S /GoTo /D (section*.3) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [458.38 472.367 518.276 481.891] >> endobj 17 0 obj << /A << /S /GoTo /D (section*.3) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [458.38 430.327 518.276 439.851] >> endobj 19 0 obj << /A << /S /URI /Type /Action /URI (https://support.industry.siemens.com/cs/us/en/view/109745821/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 386.394 518.276 397.811] >> endobj 21 0 obj << /A << /S /GoTo /D (section*.3) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [302.649 349.039 433.497 361.716] >> endobj 22 0 obj << /A << /S /GoTo /D (section*.3) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [458.38 322.336 518.276 331.86] >> endobj 24 0 obj << /A << /S /GoTo /D (section*.3) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [458.38 280.296 518.276 289.82] >> endobj 26 0 obj << /A << /S /URI /Type /Action /URI (https://www.siemens.com/gridsecurity) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [358.077 144.983 522.822 156.52] >> endobj 27 0 obj << /A << /S /GoTo /D (section*.2) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [386.143 115.095 524.579 126.632] >> endobj 28 0 obj << /A << /S /GoTo /D (section*.4) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [147.498 97.282 309.548 108.699] >> endobj 13 0 obj << /ProcSet [/PDF /Text] /Font << /F50 29 0 R /F47 30 0 R >> >> endobj 12 0 obj << /Filter /FlateDecode /Length 2522 >> stream x��Z[S�J~�W�Q�Zs����Iq�@X0Im%�A��bl�%���=7#�±W>��0kz�{��˴p���������;����2�’ #-e��A��d4I>��E������*�����r0$"-�~�d�(�0�p���z�X~��OV����fo��~;:���C8!/ �I�OG����~�-���<�7�.��x�������M+�aM�����$�~�`�p�� ���nO��0!ěM����]6’1f֛�HH l�]h���*� Qb�\�O��=� (�H��� i�;$�T#��N$(�m����4%8�/��EU�g�0��� +��NǨbBn�S�6�8�8]Mg�2�ZL-�6�0�ӽ�0�5�;��Vf�@�����#�E�9QH����3D��Ƹ%��E�?�"w�.�wӋu@�0;�P`�d+�@L;��^=��Y^u�S���q�MkQ�vq}�"�hp�Χ�۷�[�’C*g�/�^�1-ƙ��gY���8�9M)�t��pK�.’!��߳��k��J(B~��t�\泰��@�4_��;��D��#A�s���[��;ؖ���<��|iPR��WA2�$8�m�/!���C���6�C� � ������f p��y�� ��n�og50�57��Ӎ����{��q�O6����/�������ڜc@|���M��~<�Sc�03�#ע�I�����=5�M��, ��4�����l�������Ʋl@~�b�-���Z-0�8?�I�K���,�E٬��O"S��0; LV�-!vc��k���+����~r�I��7d’�eM7�scwXZ.�q�c:���� 8&�Zf�j���A[�k >y t�AM��j�j%r�9��̲e��ټ��9�~�~X������b�y��@��U� @��r+�42��2�4"�y䜼{w~::?�H�A��v���ʮ \!;1/ R]!�yK�f �o��>�ݝ�n;$0���~" ޝ�B�r�@�V��T�uWg��)��8�̱���(p�|�������F�:lxfA4�x��1F6��H��!��͓��F^���Xs��I�O%ˇ�5sӨ��@*U���Sj $ /��V�E�JT�8�d0 �Q�����ޝ� �d6�q_ظo��u�e�MA^+!����A  �}�@��Fn L��� `� ����0;no �c�}i��r���DN\(���y�� �kپ����5�����9�8������#G2�CM3�<�Nk}�/9w��B’ѶJ i��G �1����ff�@��*��’t�դ��K�zK?y��?�Q (�V��Y5��U�gx���b����-!ř4ӓ5 O%a!?�>Ⲩ�����z�(�_ϛ��"hO��aQD�+��"�¹�E>����C�H�C�t�6��R�"fO�R����B��z�D�����BQO�"& �2�]�])�3a�8��7�b���G#7�ϐaq��ϑu=� ����X9/ռ�S��5�rC��aͣe�Lg+���jQ�9>.W������ɪ��& [�ST�Ҝ�@����<�g�-\1(@a������i�� 6 �%� %w�(!n��oPZ�����q���lx �M���x�:ے 8Y�K۟�K݉4S���f�r��]�~��/ �(�E�8D�eP�r�����Oܥ�*������u��5�9X�e`��_u(Zh�’���M �֘� ��4LT�����{�C�S�b{wqu> q��ߣ<�n��5�s04Q ���R4Q ��B��z�@�%��셦~4�5:e����܆��;\�S۬ ��O#7�:�`��:뺎�A%���FK�Q����6Z�k Ր��2�h�0�m}�Z%�P��ޮ}K �:ח���’�S{}��- "��¡�l�m7%B� ���k*��W:U0����tnS��b��](x~������%�E�>ՠ��*?C�=]�Ϯ],�o���jOQ�� ��e>Y�c���k��޴�m���bF��T4��<�gE�n^9�N���(s�@�^�͟�걘����K�����a���/���>���.x�b[������l�o���[����,�u��}li�5>�ƋV��9{�����"y|;�R�Y���M_B���C�@�q?�jA�~k�XB�F$Ơ�`9��0�r�K;^}-��kx�C��?��/O�r�7���b6<�7�/��]����/�R���y I�f�f|��R���y�C�ۑ��GQ�t�P9Qc= �TYl�DD��u綪��x�M,��|�ZG�d�`�<���}_��K��wQ�7<���TD�L��~»��gM�E*�H�3��’�OT��D�%��6H��;ZER��}��UT�������-����G�W?Ƽi�L]�u’1�7Du�χ��~E�m�k�I��Q���t|!j��Q�P�^��dAg��ypo�-����� endstream endobj 31 0 obj << /D [2 0 R /XYZ 69.866 808.885 null] >> endobj 30 0 obj << /Subtype /Type1 /FirstChar 2 /Type /Font /BaseFont /UKLFEB+NimbusSanL-Regu /FontDescriptor 32 0 R /Encoding 33 0 R /LastChar 169 /Widths 34 0 R >> endobj 29 0 obj << /Subtype /Type1 /FirstChar 45 /Type /Font /BaseFont /IPYDJP+NimbusSanL-Bold /FontDescriptor 35 0 R /Encoding 33 0 R /LastChar 121 /Widths 36 0 R >> endobj 37 0 obj << /D [2 0 R /XYZ 70.866 519.299 null] >> endobj 16 0 obj << /A << /S /GoTo /D (section*.3) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 457.03 372.108 469.707] >> endobj 18 0 obj << /A << /S /GoTo /D (section*.3) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 414.989 372.108 427.667] >> endobj 20 0 obj << /A << /S /URI /Type /Action /URI (https://support.industry.siemens.com/cs/us/en/view/109745821/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 376.331 379.978 385.856] >> endobj 23 0 obj << /A << /S /GoTo /D (section*.3) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 306.998 372.108 319.676] >> endobj 25 0 obj << /A << /S /GoTo /D (section*.3) >> /Subtype /Link /C [1 0 0] /Type /Annot /H /I /Border [0 0 0] /Rect [303.117 264.958 372.108 277.636] >> endobj 14 0 obj << /Kids [2 0 R 8 0 R 10 0 R] /Type /Pages /Count 3 >> endobj 38 0 obj << /A << /S /URI /Type /Action /URI (https://www.siemens.com/gridsecurity) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [69.87 543.452 237.948 554.989] >> endobj 39 0 obj << /A << /S /URI /Type /Action /URI (https://www.first.org/cvss/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [131.954 397.405 248.203 408.942] >> endobj 40 0 obj << /A << /S /URI /Type /Action /URI (https://cwe.mitre.org/) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [69.87 307.741 163.926 319.278] >> endobj 41 0 obj << /A << /S /URI /Type /Action /URI (https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H/E:P/RL:O/RC:C) >> /C [0 1 1] /Subtype /Link /Type /Annot /H /I /Border [0 0 0] /Rect [224.029 210.182 508.922 224.129] >> endobj 42 0 obj << /ProcSet [/PDF /Text] /Font << /F50 29 0 R /F47 30 0 R >> >> endobj 8 0 obj << /Contents 43 0 R /Type /Page /Resources 42 0 R /Parent 14 0 R /Annots [38 0 R 39 0 R 40 0 R 41 0 R] /MediaBox [0 0 595.276 841.89] >> endobj 43 0 obj << /Filter /FlateDecode /Length 2992 >> stream xڝYKs�H��W�6TUL���|��(JFS����Lm�́&i��Ԉ�=�_�@M���x�"��@h<>��d3�&��ޯ�fU8��8����~zn�0�]-��:��ᬊ|�W���#g���~z.�S��4t�=M ��sx�n��σ�7�:��v���������og����g�&���vC)&��쏿�Is�M

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda