PT-2022-4634 · Measuresoft · Measuresoft Scadapro Server
Andrea Micalizzi
+3
·
Published
2022-08-23
·
Updated
2022-09-02
·
CVE-2022-2895
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Measuresoft ScadaPro Server (All Versions)
Description
The issue is related to the use of unmaintained ActiveX controls in Measuresoft ScadaPro Server, which may lead to two stack-based buffer overflow instances when processing a specific project file. This can allow a remote attacker to execute arbitrary code by exploiting the buffer overflow vulnerability. The vulnerability is associated with reading data beyond the buffer boundaries in memory.
Recommendations
For all versions of Measuresoft ScadaPro Server, consider disabling the use of ActiveX controls until a patch or update is available to mitigate the risk of exploitation. Restrict access to project files that could potentially trigger the buffer overflow to minimize the risk of remote code execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Measuresoft Scadapro Server