Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.902528
Kategorie:Buffer overflow
Titel:DATAC RealWin SCADA Server On_FC_CONNECT_FCS_a_FILE Buffer Overflow Vulnerability
Zusammenfassung:This host is running DATAC RealWin SCADA Server and is prone to;buffer overflow vulnerability.
Beschreibung:Summary:
This host is running DATAC RealWin SCADA Server and is prone to
buffer overflow vulnerability.

Vulnerability Insight:
The flaw is due to a boundary error when processing various
On_FC_BINFILE_FCS_*FILE packets, which can be exploited to cause a stack
based buffer overflow by sending specially crafted packets to port 910.

Vulnerability Impact:
Successful exploitation may allow remote attackers to execute
arbitrary code in the context of the application. Failed exploit attempts will
cause a denial-of-service condition.

Affected Software/OS:
DATAC RealFlex RealWin 2.1 (Build 6.1.10.10) and prior.

Solution:
No known solution was made available for at least one year since the disclosure
of this vulnerability. Likely none will be provided anymore. General solution options are to upgrade to a newer
release, disable respective features, remove the product or replace the product by another one.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Querverweis: BugTraq ID: 46937
Common Vulnerability Exposure (CVE) ID: CVE-2011-1563
http://www.securityfocus.com/bid/46937
http://www.exploit-db.com/exploits/17025
http://aluigi.org/adv/realwin_2-adv.txt
http://aluigi.org/adv/realwin_3-adv.txt
http://aluigi.org/adv/realwin_4-adv.txt
http://aluigi.org/adv/realwin_5-adv.txt
http://aluigi.org/adv/realwin_7-adv.txt
http://aluigi.org/adv/realwin_8-adv.txt
http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-11-080-04.pdf
http://secunia.com/advisories/43848
http://securityreason.com/securityalert/8176
http://www.vupen.com/english/advisories/2011/0742
CopyrightCopyright (C) 2011 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.