RT-Labs AB C-Open CANopen 在使用 LSS(Layered Service Specification,分层服务规范)协议配置设备时存在空指针解引用漏洞。用户应用程序定义的对象可能未包含对象 0x1018(身份对象)所需的所有子索引。一个未经认证、可访问 CAN 总线的远程攻击者(例如通过被攻陷的节点)可以在身份对象配置错误的设备上触发 LSS 协议,并可能导致设备崩溃。该漏洞已在版本 1.1.1 中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| RT-Labs AB | C-Open | 0 ~ 1.1.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet