vendor:
BACnet OPC Client
by:
Jeremy Brown
9,3
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: BACnet OPC Client
Affected Version From: 1.0.24
Affected Version To: 1.0.24
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP
2010
BACnet OPC Client Buffer Overflow Exploit
BACnet OPC Client Buffer Overflow Exploit is a vulnerability in BACnet OPC Client which allows an attacker to execute arbitrary code on the vulnerable system. The vulnerability is caused due to a boundary error when handling specially crafted BACnet packets. This can be exploited to cause a stack-based buffer overflow via an overly long, specially crafted packet sent to the affected system. Successfully tested on Windows XP Service Pack 3 with BACnet OPC CLient 1.0.24.
Mitigation:
Contact support at scadaengine.com and ask them to issue a fix.