PT-2012-5659 · Asus · Ipswcom.Dll+1
Dmitry Evdokimov
+1
·
Publicado
2012-09-15
·
Atualizado
2017-08-29
·
CVE-2012-4924
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ASUS Net4Switch version 1.0.0020
ipswcom.dll ActiveX component version 1.0.0.1
Description
The issue is related to a buffer overflow in the CxDbgPrint function within the ipswcom.dll ActiveX component. This allows remote attackers to execute arbitrary code by providing a long parameter to the
Alert method.Recommendations
For ASUS Net4Switch version 1.0.0020, consider disabling the
Alert method in the ipswcom.dll ActiveX component until a patch is available.
For ipswcom.dll ActiveX component version 1.0.0.1, restrict access to the CxDbgPrint function to minimize the risk of exploitation.Exploit
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Asus Net4Switch
Ipswcom.Dll