|
|||
Rule General Information |
---|
Release Date: | 2013-04-29 | |
Rule Name: | 7T Interactive Graphical SCADA System File Operations Buffer Overflows Vulnerability -6 (CVE-2011-1567) | |
Severity: | ||
CVE ID: | ||
CNNVD ID: | ||
Rule Protection Details |
---|
Description: | Multiple stack-based buffer overflows in IGSSdataServer.exe 9.00.00.11063 and earlier in 7-Technologies Interactive Graphical SCADA System (IGSS) allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted (1) ListAll, (2) WriteFile, (3) ReadFile, (4) Delete, (5) RenameFile, and (6) FileInfo commands in an 0xd opcode; (7) the Add, (8) ReadFile, (9) Write File, (10) Rename, (11) Delete, and (12) Add commands in an RMS report template (0x7) opcode; and (13) 0x4 command in an STDREP request (0x8) opcode to TCP port 12401. | |
Impact: | A buffer overflow vulnerability can be triggered by an attacker in the context of the vulnerable product. Further attacks include arbitrary code execution and denial of service. | |
Affected OS: | Windows | |
Reference: | ExploitDB:17024 SecurityFocusBID:46936 |
|
Solutions |
---|
No information about possible solutions is published. Please use an alternative product to substitude the affected software. |