Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q4x4-498h-293w

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

AscoServer.exe in the server in Siemens SiPass integrated MP2.6 and earlier does not properly handle IOCP RPC messages received over an Ethernet network, which allows remote attackers to write data to any memory location and consequently execute arbitrary code via crafted messages, as demonstrated by an arbitrary pointer dereference attack or a buffer overflow attack.

AscoServer.exe in the server in Siemens SiPass integrated MP2.6 and earlier does not properly handle IOCP RPC messages received over an Ethernet network, which allows remote attackers to write data to any memory location and consequently execute arbitrary code via crafted messages, as demonstrated by an arbitrary pointer dereference attack or a buffer overflow attack.

EPSS

Процентиль: 97%
0.35376
Средний

Дефекты

CWE-119

Связанные уязвимости

nvd
больше 13 лет назад

AscoServer.exe in the server in Siemens SiPass integrated MP2.6 and earlier does not properly handle IOCP RPC messages received over an Ethernet network, which allows remote attackers to write data to any memory location and consequently execute arbitrary code via crafted messages, as demonstrated by an arbitrary pointer dereference attack or a buffer overflow attack.

EPSS

Процентиль: 97%
0.35376
Средний

Дефекты

CWE-119