Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-28rp-9f44-h4v6

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause a crash of the PLC simulator present in EcoStruxureª Control Expert software when receiving a specially crafted request over Modbus.

A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause a crash of the PLC simulator present in EcoStruxureª Control Expert software when receiving a specially crafted request over Modbus.

EPSS

Процентиль: 65%
0.00505
Низкий

Дефекты

CWE-120

Связанные уязвимости

CVSS3: 7.5
nvd
почти 5 лет назад

A CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause a crash of the PLC simulator present in EcoStruxureª Control Expert software when receiving a specially crafted request over Modbus.

CVSS3: 10
fstec
почти 5 лет назад

Уязвимость программного средства программирования ПЛК (программируемых логических контроллеров) EcoStruxure Control Expert, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 65%
0.00505
Низкий

Дефекты

CWE-120