PT-2015-7256 · 3S Smart Software Solutions · Codesys Gateway Server

Josep Pi Rodriguez

·

Publicado

2015-09-16

·

Atualizado

2022-12-02

·

CVE-2015-6460

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CODESYS Gateway Server versions prior to 2.3.9.34
Description The issue is related to multiple heap-based buffer overflows that allow remote attackers to execute arbitrary code. This can be achieved via specific opcodes, including 0x3ef and 0x3f0. There is no information provided about the estimated number of potentially affected devices worldwide or details about real-world incidents where this issue was exploited.
Recommendations For versions prior to 2.3.9.34, update to version 2.3.9.34 or later to resolve the issue. As a temporary workaround, consider restricting access to the 0x3ef and 0x3f0 opcodes until a patch is applied.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-6460
ZDI-15-441
ZDI-15-442

Produtos afetados

Codesys Gateway Server