PT-2015-5002 · Scada Engine · Scada Engine Bacnet Opc Server

Josep Pi Rodriguez

·

Publicado

2015-03-14

·

Atualizado

2015-03-16

·

CVE-2015-0980

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:C
Name of the Vulnerable Software and Affected Versions SCADA Engine BACnet OPC Server versions prior to 2.1.371.24
Description The issue is related to a format string vulnerability in the BACnOPCServer.exe component, specifically in the SOAP web interface. This vulnerability allows remote attackers to execute arbitrary code by including format string specifiers in a request.
Recommendations For versions prior to 2.1.371.24, update to version 2.1.371.24 or later to resolve the issue.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-0980

Produtos afetados

Scada Engine Bacnet Opc Server