PT-2015-3053 · Ininet Solutions Gmbh · Ada Web Server+1

Aleksandr Timorin

+1

·

Published

2015-10-25

·

Updated

2015-10-27

·

CVE-2015-1001

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IniNet Solutions GmbH's SCADA Web Server versions prior to 2.02 IniNet embeddedWebServer (aka eWebServer) versions prior to 2.02
Description The issue is caused by multiple stack-based buffer overflows in the IniNet embeddedWebServer. Exploitation of these issues may allow a remote attacker to execute arbitrary code via a long field in an HTTP request.
Recommendations For versions prior to 2.02, update to version 2.02 or later to resolve the issue. As a temporary workaround, consider restricting access to the HTTP request field to minimize the risk of exploitation.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-00258
CVE-2015-1001

Affected Products

Ada Web Server
Embedded Web Server