PT-2022-3142 · Unknown · Igss Data Server

Published

2022-04-12

·

Updated

2023-02-08

·

CVE-2022-24324

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IGSS Data Server - IGSSdataServer.exe versions prior to V15.0.0.22073
Description A buffer copy without checking the size of the input issue exists, potentially leading to a stack-based buffer overflow and remote code execution when an attacker sends a specially crafted message. This could allow a remote attacker to execute arbitrary code.
Recommendations For versions prior to V15.0.0.22073, update to version V15.0.0.22073 or later to resolve the issue. As a temporary workaround, consider restricting access to the IGSSdataServer.exe module to minimize the risk of exploitation.

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2022-03821
CVE-2022-24324

Affected Products

Igss Data Server