Attack (Attack ID:324157)

Release Date2016/07/12

Attack NameSCADA Unitronics UniDownloader and VisiLogic OPLC IDE IPWorksSSL.HTTPS Memory Corruption -2 (CVE-2015-7905)

Severity

BUG ID

CVE ID

 

Description

A memory corruption vulnerability exists in Unitronics VisiLogic OPLC. The vulnerability is due to untrusted pointer dereference on the SSLCertHandle parameter of the IPWorksSSL.HTTPS ActiveX control.
Impact:Remote code execution
Affected System:Windows
Additional References:CVE-2015-7905

 

Solution

Update vendor's patch.