PT-2017-9630 · Schneider Electric · Connexium Firewalls

George Lashenko

·

Publicado

2017-02-13

·

Atualizado

2017-03-15

·

CVE-2016-8352

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Schneider Electric ConneXium firewalls version TCSEFEC23F3F20 Schneider Electric ConneXium firewalls version TCSEFEC23F3F21 Schneider Electric ConneXium firewalls version TCSEFEC23FCF20 Schneider Electric ConneXium firewalls version TCSEFEC23FCF21 Schneider Electric ConneXium firewalls version TCSEFEC2CF3F20
Description A stack-based buffer overflow issue can be triggered during the SNMP login authentication process, potentially allowing an attacker to remotely execute code.
Recommendations For version TCSEFEC23F3F20, consider disabling SNMP login authentication until a patch is available. For version TCSEFEC23F3F21, consider disabling SNMP login authentication until a patch is available. For version TCSEFEC23FCF20, consider disabling SNMP login authentication until a patch is available. For version TCSEFEC23FCF21, consider disabling SNMP login authentication until a patch is available. For version TCSEFEC2CF3F20, consider disabling SNMP login authentication until a patch is available.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-8352

Produtos afetados

Connexium Firewalls