PT-2015-7669 · Schneider Electric · Proclima

Ariele Caltabiano

·

Publicado

2015-12-08

·

Atualizado

2015-12-16

·

CVE-2015-7918

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Schneider Electric ProClima versions prior to 6.2
Description The issue is related to multiple buffer overflows in the F1BookView ActiveX control, allowing remote attackers to execute arbitrary code via various methods, including Attach, DefinedName, DefinedNameLocal, ODBCPrepareEx, ObjCreatePolygon, SetTabbedTextEx, and SetValidationRule.
Recommendations For versions prior to 6.2, update to version 6.2 or later to resolve the issue. As a temporary workaround, consider disabling the Attach, DefinedName, DefinedNameLocal, ODBCPrepareEx, ObjCreatePolygon, SetTabbedTextEx, and SetValidationRule methods until a patch is available. Restrict access to the F1BookView ActiveX control to minimize the risk of exploitation.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-7918
ZDI-15-625
ZDI-15-630
ZDI-15-631
ZDI-15-632
ZDI-15-633
ZDI-15-634
ZDI-15-635

Produtos afetados

Proclima