vendor:
KingScada
by:
James Fitts
7,5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: KingScada
Affected Version From: 3.1.1.4
Affected Version To: 3.1.2.13
Patch Exists: YES
Related CWE: CVE-2014-0787
CPE: a:wellintech:king_scada
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3
2014
KingScada AlarmServer Stack Buffer Overflow
This module exploits a stack based buffer overflow found in KingScada < 3.1.2.13. The vulnerability is triggered when sending a specially crafted packet to the 'AlarmServer' (AEserver.exe) service listening on port 12401. During the parsing of the packet the 3rd dword is used as a size value for a memcpy operation which leads to an overflown stack buffer.
Mitigation:
Upgrade to KingScada version 3.1.2.13 or later.