PT-2022-2280 · Unknown · Interactive Graphical Scada System Data Server
Vyacheslav Moskvin
·
Published
2022-02-08
·
Updated
2022-02-17
·
CVE-2022-24313
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Interactive Graphical SCADA System Data Server versions V15.0.0.22020 and prior
Description
The issue is caused by a stack-based buffer overflow due to a buffer copy without checking the size of the input. This could potentially lead to remote code execution when an attacker sends a specially crafted message.
Recommendations
For versions V15.0.0.22020 and prior, update to a version that fixes the buffer overflow issue to prevent remote code execution.
As a temporary workaround, consider restricting access to the system to minimize the risk of exploitation.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Interactive Graphical Scada System Data Server