CVE-2017-6023
Severity CVSS v4.0:
Pending analysis
Type:
CWE-121
Stack-based Buffer Overflow
Publication date:
16/03/2017
Last modified:
20/04/2025
Description
An issue was discovered in Fatek Automation PLC Ethernet Module. The affected Ether_cfg software configuration tool runs on the following Fatek PLCs: CBEH versions prior to V3.6 Build 170215, CBE versions prior to V3.6 Build 170215, CM55E versions prior to V3.6 Build 170215, and CM25E versions prior to V3.6 Build 170215. A stack-based buffer overflow vulnerability has been identified, which may allow remote code execution or crash the affected device.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
9.00
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:fatek:ethernet_module_configuration_tool_cbe_firmware:*:*:*:*:*:*:*:* | 3.5 (including) | |
| cpe:2.3:o:fatek:ethernet_module_configuration_tool_cbeh_firmware:*:*:*:*:*:*:*:* | 3.5 (including) | |
| cpe:2.3:o:fatek:ethernet_module_configuration_tool_cm25e_firmware:*:*:*:*:*:*:*:* | 3.5 (including) | |
| cpe:2.3:o:fatek:ethernet_module_configuration_tool_cm55e_firmware:*:*:*:*:*:*:*:* | 3.5 (including) | |
| cpe:2.3:h:fatek:plc_ethernet_module:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



