CVE-2023-7244: Cisa Icsnpp-Ethercat

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

Industrial Control Systems Network Protocol Parsers (ICSNPP) - Ethercat Zeek Plugin versions d78dda6 and prior are vulnerable to out-of-bounds write in their primary analyses function for Ethercat communication packets. This could allow an attacker to cause arbitrary code execution.

Affected products

  • Cisa Icsnpp-Ethercat: up to and including d78dda6

Published 2024-03-01. Last modified 2026-06-17.