CVE-2011-3321

Heap-based buffer overflow in the Siemens WinCC Runtime Advanced Loader, as used in SIMATIC WinCC flexible Runtime and SIMATIC WinCC (TIA Portal) Runtime Advanced, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted packet to TCP port 2308.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:siemens:simatic_wincc_flexible_runtime:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:simatic_wincc_runtime:-:*:*:*:advanced:*:*:*

History

21 Nov 2024, 01:30

Type Values Removed Values Added
References () http://cache.automation.siemens.com/dnl/jI/jI0NDY5AAAA_29054992_FAQ/Siemens_Security_Advisory_SSA-460621_V1_2.pdf - () http://cache.automation.siemens.com/dnl/jI/jI0NDY5AAAA_29054992_FAQ/Siemens_Security_Advisory_SSA-460621_V1_2.pdf -
References () http://secunia.com/advisories/46011 - Vendor Advisory () http://secunia.com/advisories/46011 - Vendor Advisory
References () http://support.automation.siemens.com/WW/view/en/29054992 - () http://support.automation.siemens.com/WW/view/en/29054992 -
References () http://www.us-cert.gov/control_systems/pdf/ICSA-11-244-01.pdf - US Government Resource () http://www.us-cert.gov/control_systems/pdf/ICSA-11-244-01.pdf - US Government Resource
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/69803 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/69803 -

Information

Published : 2011-09-16 12:35

Updated : 2024-11-21 01:30


NVD link : CVE-2011-3321

Mitre link : CVE-2011-3321

CVE.ORG link : CVE-2011-3321


JSON object : View

Products Affected

siemens

  • simatic_wincc_flexible_runtime
  • simatic_wincc_runtime
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer