CVE-2017-11401

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/11/2017
Last modified:
20/04/2025

Description

An issue has been discovered on the Belden Hirschmann Tofino Xenon Security Appliance before 03.2.00. Improper handling of the mbap.length field of ModBus packets in the ModBus DPI filter allows an attacker to send malformed/crafted packets to a protected asset, bypassing function code filtering.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:belden:tofino_xenon_security_appliance_firmware:*:*:*:*:*:*:*:* 3.1.0 (including)
cpe:2.3:h:belden:tofino_xenon_security_appliance:-:*:*:*:*:*:*:*