PT-2021-4661 · Fatek · Fatek Automation Communication Server
Nattisamson
·
Published
2021-06-11
·
Updated
2021-10-20
·
CVE-2021-38432
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FATEK Automation Communication Server versions 1.13 and prior
Description
The issue is related to a stack-based buffer overflow condition due to the lack of proper validation of user-supplied data. This could allow an attacker to remotely execute code by sending specially crafted requests, potentially resulting in remote code execution or denial of service.
Recommendations
For versions 1.13 and prior, update to a version that properly validates user-supplied data to prevent stack-based buffer overflow conditions.
As a temporary workaround, consider restricting access to the server to minimize the risk of exploitation until a patch is available.
Fix
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fatek Automation Communication Server