Resource exhaustion in Ovarro products - CVE-2021-22642
Published: March 24, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can use specially crafted invalid Modbus frames, trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
TBox RM2
TBox TG2
TBox MS-CPU32
TBox MS-CPU32-S2
TWinSoft
How to mitigate CVE-2021-22642
TBox MS-CPU32-S2 - update to 1.46
TWinSoft - update to 12.4