vendor:
AlphaStor Device Manager
by:
James Fitts
7,8
CVSS
HIGH
Stack Based Buffer Overflow
119
CWE
Product Name: AlphaStor Device Manager
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows Server 2003 SP2 EN
2013
EMC AlphaStor Device Manager Opcode 0x72
This module exploits a stack based buffer overflow vulnerability found in EMC Alphastor Device Manager. The overflow is triggered when sending a specially crafted packet to the rrobotd.exe service listening on port 3000. During the copying of strings to the stack an unbounded sprintf() function overwrites the return pointer leading to remote code execution.
Mitigation:
N/A