PT-2008-1822 · Ge Fanuc · Ge Fanuc Cimplicity Hmi Scada
Eyal Udassin
·
Published
2008-01-29
·
Updated
2018-10-15
·
CVE-2008-0176
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
GE Fanuc CIMPLICITY HMI SCADA system versions prior to 7.0 SIM 9
GE Fanuc CIMPLICITY HMI SCADA system versions prior to 6.1 SP6 Hot fix - 010708 162517 6106
Description
The issue is related to a heap-based buffer overflow in the w32rtr.exe component. This allows remote attackers to execute arbitrary code via unknown vectors.
Recommendations
For GE Fanuc CIMPLICITY HMI SCADA system versions prior to 7.0 SIM 9, update to version 7.0 SIM 9 or later.
For GE Fanuc CIMPLICITY HMI SCADA system versions prior to 6.1 SP6 Hot fix - 010708 162517 6106, apply Hot fix - 010708 162517 6106 or later.
Fix
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ge Fanuc Cimplicity Hmi Scada