PT-2024-7814 · Unknown · Automation License Manager V6.0+2

Published

2024-09-10

·

Updated

2024-09-14

·

CVE-2024-44087

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Automation License Manager V5 (All versions) Automation License Manager V6.0 (All versions) Automation License Manager V6.2 (All versions prior to V6.2 Upd3)
Description The issue is related to an integer overflow in the Automation License Manager. This could allow a remote attacker to cause a denial of service by sending specially crafted network packets using port 4410/tcp. The affected applications do not properly validate certain fields in incoming network packets, which can lead to a crash of the application. This denial of service condition could prevent legitimate users from using subsequent products that rely on the affected application for license verification.
Recommendations For Automation License Manager V5 (All versions), consider disabling the application's network functionality or restricting access to port 4410/tcp until a patch is available. For Automation License Manager V6.0 (All versions), restrict access to the vulnerable network packets on port 4410/tcp to minimize the risk of exploitation. For Automation License Manager V6.2 (All versions prior to V6.2 Upd3), update to V6.2 Upd3 or later to resolve the issue. As a temporary workaround, consider disabling the application's network functionality or restricting access to port 4410/tcp until the update can be applied.

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-09314
CVE-2024-44087

Affected Products

Automation License Manager V5
Automation License Manager V6.0
Automation License Manager V6.2