Описание
Use-after-free vulnerability in Control Microsystems ClearSCADA 2005, 2007, and 2009 before R2.3 and R1.4, as used in SCX before 67 R4.5 and 68 R3.9, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified long strings that trigger heap memory corruption.
Ссылки
- Third Party Advisory
- Broken LinkThird Party Advisory
- Broken Link
- Third Party AdvisoryVDB Entry
- PatchThird Party AdvisoryUS Government Resource
- PatchThird Party AdvisoryUS Government Resource
- Third Party Advisory
- Broken LinkThird Party Advisory
- Broken Link
- Third Party AdvisoryVDB Entry
- PatchThird Party AdvisoryUS Government Resource
- PatchThird Party AdvisoryUS Government Resource
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:aveva:clearscada:2005:*:*:*:*:*:*:*
cpe:2.3:a:aveva:clearscada:2007:*:*:*:*:*:*:*
cpe:2.3:a:aveva:clearscada:2009:*:*:*:*:*:*:*
Конфигурация 2Версия до r4.5 (исключая)Версия до r3.9 (исключая)
Одно из
cpe:2.3:a:schneider-electric:scx_67:*:*:*:*:*:*:*:*
cpe:2.3:a:schneider-electric:scx_68:*:*:*:*:*:*:*:*
EPSS
Процентиль: 89%
0.04609
Низкий
10 Critical
CVSS2
Дефекты
CWE-399
Связанные уязвимости
github
больше 3 лет назад
Use-after-free vulnerability in Control Microsystems ClearSCADA 2005, 2007, and 2009 before R2.3 and R1.4, as used in SCX before 67 R4.5 and 68 R3.9, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified long strings that trigger heap memory corruption.
EPSS
Процентиль: 89%
0.04609
Низкий
10 Critical
CVSS2
Дефекты
CWE-399