PT-2012-5971 · Siemens · Sipass Integrated

Lucas Apa

·

Publicado

2012-11-01

·

Atualizado

2013-05-21

·

CVE-2012-5409

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Siemens SiPass integrated versions MP2.6 and earlier
Description The issue arises from improper handling of IOCP RPC messages by AscoServer.exe in the server, allowing remote attackers to write data to any memory location and execute arbitrary code via crafted messages. This can be achieved through methods such as an arbitrary pointer dereference attack or a buffer overflow attack.
Recommendations For versions MP2.6 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-5409

Produtos afetados

Sipass Integrated