Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7896-447p-7w4j

Опубликовано: 03 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.2
CVSS3: 7.5

Описание

Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE.

When the REST interface is enabled by the user, and an attacker gains access to the control network, and CVE-2025-6074 is exploited, the attacker can use the JSON configuration to overflow the date of expiration field.This issue affects RMC-100: from 2105457-043 through 2105457-045; RMC-100 LITE: from 2106229-015 through 2106229-016.

Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE.

When the REST interface is enabled by the user, and an attacker gains access to the control network, and CVE-2025-6074 is exploited, the attacker can use the JSON configuration to overflow the date of expiration field.This issue affects RMC-100: from 2105457-043 through 2105457-045; RMC-100 LITE: from 2106229-015 through 2106229-016.

EPSS

Процентиль: 18%
0.00058
Низкий

8.2 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-121

Связанные уязвимости

CVSS3: 7.5
nvd
7 месяцев назад

Stack-based Buffer Overflow vulnerability in ABB RMC-100, ABB RMC-100 LITE. When the REST interface is enabled by the user, and an attacker gains access to the control network, and CVE-2025-6074 is exploited, the attacker can use the JSON configuration to overflow the date of expiration field.This issue affects RMC-100: from 2105457-043 through 2105457-045; RMC-100 LITE: from 2106229-015 through 2106229-016.

CVSS3: 7.5
fstec
7 месяцев назад

Уязвимость реализации протокола MQTT веб-интерфейса микропрограммного обеспечения контроллеров ABB RMC-100 и RMC-100-LITE, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 18%
0.00058
Низкий

8.2 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-121