Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2011-5007

Overview

Vulnerability Score 10.0 10.0
CVE Id CVE-2011-5007
Last Modified 20 May 2013 11:12:51
Published 24 Dec 2011 08:55:04
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2011-5007

Summary

Stack-based buffer overflow in the CmpWebServer component in 3S CoDeSys 3.4 SP4 Patch 2 and earlier, as used on the ABB AC500 PLC and possibly other products, allows remote attackers to execute arbitrary code via a long URI to TCP port 8080.

Vulnerable Systems

Application

  • 3ssoftware Codesys 3.4


References

MISC - http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-11-336-01A.pdf

MISC - http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-11-336-01.pdf

EXPLOIT-DB - 18187

SECUNIA - 47018

BUGTRAQ - 20111129 Vulnerabilities in 3S CoDeSys 3.4 SP4 Patch 2

OSVDB - 77387

MISC - http://aluigi.altervista.org/adv/codesys_1-adv.txt

MISC - http://ics-cert.us-cert.gov/advisories/ICSA-12-320-01


Last Updated: 27 May 2016 10:57:17