Back
CVE-2017-6023
CRITICAL
An issue was discovered in Fatek Automation PLC Ethernet Module. The affected Ether_cfg software configuration tool runs on the following Fatek PLCs: CBEH versions prior to V3.6 Build 170215, CBE versions prior to V3.6 Build 170215, CM55E versions prior to V3.6 Build 170215, and CM25E versions prior to V3.6 Build 170215. A stack-based buffer overflow vulnerability has been identified, which may allow remote code execution or crash the affected device.
Published: Mar 16, 2017
Modified: Jun 17, 2026
CWE-121
CWE-119
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (4)
| Vendor | Product | Version |
|---|---|---|
| fatek | ethernet_module_configuration_tool_cbe_firmware | * |
| fatek | ethernet_module_configuration_tool_cbeh_firmware | * |
| fatek | ethernet_module_configuration_tool_cm25e_firmware | * |
| fatek | ethernet_module_configuration_tool_cm55e_firmware | * |
GitHub Security Advisory GHSA-jwfc-gwh4-6qmp
An issue was discovered in Fatek Automation PLC Ethernet Module. The affected Ether_cfg software...
References (4)
- http://www.securityfocus.com/bid/96892 Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-17-073-01 Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/96892 Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-17-073-01 Third Party Advisory, US Government Resource
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
4.41%
Top 10% most likely to be exploited
Threat Score
40.5 / 100
Data Sources
NVD
EPSS
GitHub