Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-5409

Опубликовано: 01 нояб. 2012
Источник: nvd
CVSS2: 10
EPSS Средний

Описание

AscoServer.exe in the server in Siemens SiPass integrated MP2.6 and earlier does not properly handle IOCP RPC messages received over an Ethernet network, which allows remote attackers to write data to any memory location and consequently execute arbitrary code via crafted messages, as demonstrated by an arbitrary pointer dereference attack or a buffer overflow attack.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:siemens:sipass_integrated:*:*:*:*:*:*:*:*
Версия до mp2.6 (включая)

EPSS

Процентиль: 97%
0.35376
Средний

10 Critical

CVSS2

Дефекты

CWE-119

Связанные уязвимости

github
больше 3 лет назад

AscoServer.exe in the server in Siemens SiPass integrated MP2.6 and earlier does not properly handle IOCP RPC messages received over an Ethernet network, which allows remote attackers to write data to any memory location and consequently execute arbitrary code via crafted messages, as demonstrated by an arbitrary pointer dereference attack or a buffer overflow attack.

EPSS

Процентиль: 97%
0.35376
Средний

10 Critical

CVSS2

Дефекты

CWE-119