vendor:
InBatch
by:
Luigi Auriemma
7,5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: InBatch
Affected Version From: lm_tcp <= 9.0.0 0248.18.0.0 (InBatch <= 9.0sp1)
Affected Version To: lm_tcp <= 9.0.0 0248.18.0.0 (InBatch <= 9.0sp1)
Patch Exists: YES
Related CWE: N/A
CPE: a:wonderware:inbatch
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux
2010
Buffer Overflow in Wonderware InBatch
The lm_tcp service listens (manually or automatically during the launching of 'Environment Display/Manager') on port 9001 and is vulnerable to a buffer overflow during the copying of a string in a buffer of 150 bytes which is part of a fixed structure. The overflow (max 19204 chars) allows only to overwrite the two memory pointers located after the space assigned to the copying of the string and they are immediately used for two memset(buffer, 0, 2) operations with the consequent effect of writing a 16bit 0x0000 in an arbitrary memory location.
Mitigation:
Upgrade to the latest version of Wonderware InBatch