B
今週中
Savannah lwIP SMTPクライアントのバージョン2.2.1に、入力サイズのチェック不足によるバッファオーバーフローの脆弱性(CVE-2026-153…
📌 一言でいうと
Savannah lwIP SMTPクライアントのバージョン2.2.1に、入力サイズのチェック不足によるバッファオーバーフローの脆弱性(CVE-2026-15340)が発見されました。この脆弱性が悪用されると、デバイスのクラッシュやリモートコード実行(RCE)を許す可能性があります。CVSS v3スコアは9.8と非常に高く、エネルギーや水処理などの重要インフラセクターに影響が及ぶ可能性があります。
🔍該当判定
- Savannah社の製品(産業用制御システム等)を利用している
- デバイス内で「lwIP SMTP client」という通信機能が動作している
- lwIP SMTP clientのバージョンが「2.2.1」である
上記いずれにも該当しない → 静観でOK
✅該当時の対応
影響を受けるバージョン(2.2.1)を使用している場合は、提供されているパッチ(patch_125_smtp_txbuf.diff または git commit 614420f82c8729d070e01464c0dddb3c9525c772)を適用してください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】Savannah lwIP SMTP client CVE-2026-15340 対応について
お疲れさまです。Savannah lwIP SMTP clientの脆弱性に関する情報共有です。
■ 概要
入力サイズのチェック不足によるバッファオーバーフローの脆弱性が確認されました。CVSS v3スコアは9.8(CRITICAL)であり、リモートコード実行(RCE)やデバイスのクラッシュを招く恐れがあります。
■ 影響範囲
- 対象製品: Savannah lwIP SMTP client
- 対象バージョン: 2.2.1
■ 対応手順
1. 利用中のバージョンを確認し、2.2.1であるか特定してください。
2. 提供されているパッチ(patch_125_smtp_txbuf.diff)または git commit (614420f82c8729d070e01464c0dddb3c9525c772) を適用してください。
■ 参考情報
- CISA ICS Advisory ICSA-26-279-02
対応優先度: 高
対応期限: 速やかに
お疲れさまです。Savannah lwIP SMTP clientの脆弱性に関する情報共有です。
■ 概要
入力サイズのチェック不足によるバッファオーバーフローの脆弱性が確認されました。CVSS v3スコアは9.8(CRITICAL)であり、リモートコード実行(RCE)やデバイスのクラッシュを招く恐れがあります。
■ 影響範囲
- 対象製品: Savannah lwIP SMTP client
- 対象バージョン: 2.2.1
■ 対応手順
1. 利用中のバージョンを確認し、2.2.1であるか特定してください。
2. 提供されているパッチ(patch_125_smtp_txbuf.diff)または git commit (614420f82c8729d070e01464c0dddb3c9525c772) を適用してください。
■ 参考情報
- CISA ICS Advisory ICSA-26-279-02
対応優先度: 高
対応期限: 速やかに
Subject: [Security Advisory] Savannah lwIP SMTP client CVE-2026-15340
Dear team,
We are sharing information regarding a critical vulnerability in the Savannah lwIP SMTP client.
■ Overview
A buffer overflow vulnerability (CVE-2026-15340) has been discovered due to a lack of input size validation. With a CVSS v3 score of 9.8, this flaw could allow remote code execution (RCE) or cause the device to crash.
■ Affected Scope
- Product: Savannah lwIP SMTP client
- Version: 2.2.1
■ Remediation Steps
1. Identify if the deployed version is 2.2.1.
2. Apply the provided patch (patch_125_smtp_txbuf.diff) or the corresponding git commit (614420f82c8729d070e01464c0dddb3c9525c772).
■ Reference
- CISA ICS Advisory ICSA-26-279-02
Priority: High
Deadline: Immediate
Dear team,
We are sharing information regarding a critical vulnerability in the Savannah lwIP SMTP client.
■ Overview
A buffer overflow vulnerability (CVE-2026-15340) has been discovered due to a lack of input size validation. With a CVSS v3 score of 9.8, this flaw could allow remote code execution (RCE) or cause the device to crash.
■ Affected Scope
- Product: Savannah lwIP SMTP client
- Version: 2.2.1
■ Remediation Steps
1. Identify if the deployed version is 2.2.1.
2. Apply the provided patch (patch_125_smtp_txbuf.diff) or the corresponding git commit (614420f82c8729d070e01464c0dddb3c9525c772).
■ Reference
- CISA ICS Advisory ICSA-26-279-02
Priority: High
Deadline: Immediate