If an attacker were to access memory locations of LS ELECTRIC XBC-DN32U with operating system version 01.80 that are outside of the communication buffer, the device stops operating. This could allow an attacker to cause a denial-of-service condition.
Workaround:
The product reads or writes to a buffer using an index or pointer that references a memory location after the end of the buffer.
Link | Tags |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-23-040-02 | us government resource third party advisory broken link |