PT-2021-4661 · Fatek · Fatek Automation Communication Server

Nattisamson

·

Published

2021-06-11

·

Updated

2021-10-20

·

CVE-2021-38432

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FATEK Automation Communication Server versions 1.13 and prior
Description The issue is related to a stack-based buffer overflow condition due to the lack of proper validation of user-supplied data. This could allow an attacker to remotely execute code by sending specially crafted requests, potentially resulting in remote code execution or denial of service.
Recommendations For versions 1.13 and prior, update to a version that properly validates user-supplied data to prevent stack-based buffer overflow conditions. As a temporary workaround, consider restricting access to the server to minimize the risk of exploitation until a patch is available.

Fix

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05354
CVE-2021-38432
ZDI-21-1164

Affected Products

Fatek Automation Communication Server