CVE-2012-5409

AscoServer.exe in the server in Siemens SiPass integrated MP2.6 and earlier does not properly handle IOCP RPC messages received over an Ethernet network, which allows remote attackers to write data to any memory location and consequently execute arbitrary code via crafted messages, as demonstrated by an arbitrary pointer dereference attack or a buffer overflow attack.
Configurations

Configuration 1 (hide)

cpe:2.3:a:siemens:sipass_integrated:*:*:*:*:*:*:*:*

History

21 Nov 2024, 01:44

Type Values Removed Values Added
References () http://ics-cert.us-cert.gov/advisories/ICSA-12-305-01 - () http://ics-cert.us-cert.gov/advisories/ICSA-12-305-01 -
References () http://ioactive.com/pdfs/SIEMENS_Sipass_Integrated_Ethernet_Bus_Arbitrary_Pointer_Dereference_V4.pdf - () http://ioactive.com/pdfs/SIEMENS_Sipass_Integrated_Ethernet_Bus_Arbitrary_Pointer_Dereference_V4.pdf -
References () http://secunia.com/advisories/50900 - Vendor Advisory () http://secunia.com/advisories/50900 - Vendor Advisory
References () http://www.osvdb.org/86129 - () http://www.osvdb.org/86129 -
References () http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-938777.pdf - Vendor Advisory () http://www.siemens.com/corporate-technology/pool/de/forschungsfelder/siemens_security_advisory_ssa-938777.pdf - Vendor Advisory

Information

Published : 2012-11-01 10:44

Updated : 2024-11-21 01:44


NVD link : CVE-2012-5409

Mitre link : CVE-2012-5409

CVE.ORG link : CVE-2012-5409


JSON object : View

Products Affected

siemens

  • sipass_integrated
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer