Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2013-0662

Overview

Vulnerability Score 9.3 9.3
CVE Id CVE-2013-0662
Last Modified 08 Oct 2015 10:37:36
Published 01 Apr 2014 02:17:08
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2013-0662

Summary

Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow remote attackers to execute arbitrary code via a large buffer-size value in a Modbus Application Header.

Vulnerable Systems

Application

  • Schneider-electric Concept 2.6

  • Schneider-electric Modbus Serial Driver 1.10

  • Schneider-electric Modbus Serial Driver 2.2

  • Schneider-electric Modbus Serial Driver 3.2

  • Schneider-electric Modbuscommdtm Sl 2.1.2

  • Schneider-electric Opc Factory Server 3.34

  • Schneider-electric Opc Factory Server 3.35

  • Schneider-electric Opc Factory Server 3.5.0

  • Schneider-electric Pl7 4.5

  • Schneider-electric Powersuite 2.6

  • Schneider-electric Sft2841 13.1

  • Schneider-electric Sft2841 14.0

  • Schneider-electric Somachine 2.0

  • Schneider-electric Somachine 3.0

  • Schneider-electric Somachine 3.1

  • Schneider-electric Somove 1.7

  • Schneider-electric Twidosuite 2.31.04

  • Schneider-electric Unity Pro 6.0

  • Schneider-electric Unity Pro 7.0

  • Schneider-electric Unityloader 2.3


References

MISC - http://ics-cert.us-cert.gov/advisories/ICSA-14-086-01

CONFIRM - http://download.schneider-electric.com/files?p_Doc_Ref=SEVD%202013-070-01

BID - 66500


Last Updated: 27 May 2016 11:04:49