Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-frmp-r2qj-7qjr

Опубликовано: 12 фев. 2022
Источник: github
Github: Не прошло ревью

Описание

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution due to missing length check on user supplied data, when a constructed message is received on the network. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and prior)

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution due to missing length check on user supplied data, when a constructed message is received on the network. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and prior)

EPSS

Процентиль: 85%
0.02468
Низкий

Дефекты

CWE-120

Связанные уязвимости

CVSS3: 9.8
nvd
почти 4 года назад

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution due to missing length check on user supplied data, when a constructed message is received on the network. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and prior)

CVSS3: 9.8
fstec
больше 4 лет назад

Уязвимость интерактивной графической SCADA системы Interactive Graphical SCADA System (IGSS), вызванная переполнением буфера на стеке, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 85%
0.02468
Низкий

Дефекты

CWE-120