PT-2012-5659 · Asus · Ipswcom.Dll+1
Dmitry Evdokimov
+1
·
Published
2012-09-15
·
Updated
2017-08-29
·
CVE-2012-4924
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ASUS Net4Switch version 1.0.0020
ipswcom.dll ActiveX component version 1.0.0.1
Description
The issue is related to a buffer overflow in the CxDbgPrint function within the ipswcom.dll ActiveX component. This allows remote attackers to execute arbitrary code by providing a long parameter to the
Alert method.Recommendations
For ASUS Net4Switch version 1.0.0020, consider disabling the
Alert method in the ipswcom.dll ActiveX component until a patch is available.
For ipswcom.dll ActiveX component version 1.0.0.1, restrict access to the CxDbgPrint function to minimize the risk of exploitation.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Asus Net4Switch
Ipswcom.Dll