PT-2017-16841 · 3S Smart Software Solutions · Codesys Web Server
Published
2017-05-19
·
Updated
2019-10-09
·
CVE-2017-6025
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CODESYS Web Server versions 2.3 and prior
Description
A Stack Buffer Overflow issue was discovered in the CODESYS Web Server, which is part of the CODESYS WebVisu web browser visualization software. This issue can be exploited by providing overly long strings to functions that handle XML, potentially allowing an attacker to crash the application or run arbitrary code, as the function does not verify string size before copying to memory.
Recommendations
For CODESYS Web Server versions 2.3 and prior, update to a version later than 2.3 to resolve the issue. As a temporary workaround, consider restricting input to functions that handle XML to prevent overly long strings from being processed.
Fix
Stack Overflow
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Codesys Web Server