CVE-2022-4856

A vulnerability has been found in Modbus Tools Modbus Slave up to 7.5.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file mbslave.exe of the component mbs File Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-217021 was assigned to this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:modbustools:modbus_slave:*:*:*:*:*:*:*:*

History

29 Feb 2024, 01:36

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad ha sido encontrada en Modbus Tools Modbus Slave hasta 7.5.1 y clasificada como crítica. Una función desconocida del archivo mbslave.exe del componente mbs File Handler es afectada por esta vulnerabilidad. La manipulación provoca un desbordamiento del búfer. El ataque se puede lanzar de forma remota. El exploit ha sido divulgado al público y puede utilizarse. A esta vulnerabilidad se le asignó el identificador VDB-217021.

09 Jan 2023, 18:21

Type Values Removed Values Added
References (MISC) https://github.com/Durian1546/vul/blob/main/webray.com.cn/Modbus%20Slave/Modbus%20Slave%20(version%207.5.1%20and%20earlier)%20mbs%20file%20has%20a%20buffer%20overflow%20vulnerability.md - (MISC) https://github.com/Durian1546/vul/blob/main/webray.com.cn/Modbus%20Slave/Modbus%20Slave%20(version%207.5.1%20and%20earlier)%20mbs%20file%20has%20a%20buffer%20overflow%20vulnerability.md - Exploit, Patch, Third Party Advisory
References (MISC) https://vuldb.com/?id.217021 - (MISC) https://vuldb.com/?id.217021 - Third Party Advisory
References (MISC) https://github.com/Durian1546/vul/blob/main/webray.com.cn/Modbus%20Slave/poc/poc.mbs - (MISC) https://github.com/Durian1546/vul/blob/main/webray.com.cn/Modbus%20Slave/poc/poc.mbs - Third Party Advisory
References (MISC) https://vuldb.com/?ctiid.217021 - (MISC) https://vuldb.com/?ctiid.217021 - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
First Time Modbustools modbus Slave
Modbustools
CPE cpe:2.3:a:modbustools:modbus_slave:*:*:*:*:*:*:*:*

30 Dec 2022, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-12-30 10:15

Updated : 2024-04-11 01:17


NVD link : CVE-2022-4856

Mitre link : CVE-2022-4856

CVE.ORG link : CVE-2022-4856


JSON object : View

Products Affected

modbustools

  • modbus_slave
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')