PT-2014-1965 · Schneider Electric · Modbus Serial Driver

Alejandro Parodi

·

Published

2014-03-28

·

Updated

2022-02-03

·

CVE-2013-0662

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Schneider Electric Modbus Serial Driver versions 1.10 through 3.2
Description The issue is caused by multiple stack-based buffer overflows in ModbusDrv.exe, allowing remote attackers to execute arbitrary code via a large buffer-size value in a Modbus Application Header. This can be exploited by sending a specially crafted request with a large buffer-size value, potentially leading to code execution.
Recommendations For versions 1.10 through 3.2, update to a version that fixes the buffer overflow issue in ModbusDrv.exe to prevent remote code execution. As a temporary workaround, consider restricting access to the Modbus Application Header to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-00202
CVE-2013-0662

Affected Products

Modbus Serial Driver