PT-2022-2280 · Unknown · Interactive Graphical Scada System Data Server

Vyacheslav Moskvin

·

Published

2022-02-08

·

Updated

2022-02-17

·

CVE-2022-24313

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Interactive Graphical SCADA System Data Server versions V15.0.0.22020 and prior
Description The issue is caused by a stack-based buffer overflow due to a buffer copy without checking the size of the input. This could potentially lead to remote code execution when an attacker sends a specially crafted message.
Recommendations For versions V15.0.0.22020 and prior, update to a version that fixes the buffer overflow issue to prevent remote code execution. As a temporary workaround, consider restricting access to the system to minimize the risk of exploitation.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02445
CVE-2022-24313
ZDI-22-325

Affected Products

Interactive Graphical Scada System Data Server