RULE(RULE ID:705188)

Rule General Information
Release Date: 2013-04-29
Rule Name: 7T Interactive Graphical SCADA System File Operations Buffer Overflows Vulnerability -6 (CVE-2011-1567)
Severity:
CVE ID:
CNNVD ID:
Rule Protection Details
Description: Multiple stack-based buffer overflows in IGSSdataServer.exe 9.00.00.11063 and earlier in 7-Technologies Interactive Graphical SCADA System (IGSS) allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted (1) ListAll, (2) WriteFile, (3) ReadFile, (4) Delete, (5) RenameFile, and (6) FileInfo commands in an 0xd opcode; (7) the Add, (8) ReadFile, (9) Write File, (10) Rename, (11) Delete, and (12) Add commands in an RMS report template (0x7) opcode; and (13) 0x4 command in an STDREP request (0x8) opcode to TCP port 12401.
Impact: A buffer overflow vulnerability can be triggered by an attacker in the context of the vulnerable product. Further attacks include arbitrary code execution and denial of service.
Affected OS: Windows
Reference: ExploitDB:17024
SecurityFocusBID:46936
Solutions
No information about possible solutions is published. Please use an alternative product to substitude the affected software.