CVE-2017-11401
Last modified
CVE-2017-11401 is a vulnerability of currently unknown severity. An issue has been discovered on the Belden Hirschmann Tofino Xenon Security Appliance before 03.2.00. Improper handling of the mbap.length field of ModBus packets in the ModBus DPI filter allows an attacker to send malformed/crafted packets to a protected asset, bypassing function code filtering.. EPSS estimates a 1.40% chance of exploitation in the next 30 days.
Description
An issue has been discovered on the Belden Hirschmann Tofino Xenon Security Appliance before 03.2.00. Improper handling of the mbap.length field of ModBus packets in the ModBus DPI filter allows an attacker to send malformed/crafted packets to a protected asset, bypassing function code filtering.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Belden | Tofino Xenon Security Appliance Firmware | <= 3.1.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-11401?
How severe is CVE-2017-11401?
How do I fix CVE-2017-11401?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-11396Vulnerability issues with the web service inspection of inpu…7.2
- CVE-2017-11397A service DLL preloading vulnerability in Trend Micro Encryp…
- CVE-2017-11398A session hijacking via log disclosure vulnerability in Tren…
- CVE-2017-11399Integer overflow in the ape_decode_frame function in libavco…
- CVE-2017-1140IBM Business Process Manager 8.0 and 8.5 are vulnerable to c…
- CVE-2017-11400An issue has been discovered on the Belden Hirschmann Tofino…
- CVE-2017-11402An issue has been discovered on the Belden Hirschmann Tofino…
- CVE-2017-11403The ReadMNGImage function in coders/png.c in GraphicsMagick …
- CVE-2017-11404In CMS Made Simple (CMSMS) 2.2.2, remote authenticated admin…
- CVE-2017-11405In CMS Made Simple (CMSMS) 2.2.2, remote authenticated admin…
- CVE-2017-11406In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the DOCSIS …
- CVE-2017-11407In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the MQ diss…
Are you affected by CVE-2017-11401?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
