vendor:
WinProladder
by:
james fitts
8
CVSS
HIGH
Stack-based Buffer Overflow
119
CWE
Product Name: WinProladder
Affected Version From: 3.11 Build 14701
Affected Version To: 3.11 Build 14701
Patch Exists: NO
Related CWE: CVE-2016-8377
CPE: a:fatek_automation:winproladder
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 EN
2016
Fatek Automation PLC WinProladder Stack-based Buffer Overflow
This module exploits a stack based buffer overflow found in Fatek Automation PLC WinProladder v3.11 Build 14701. The vulnerability is triggered when a client connects to a listening server. The client does not properly sanitize the length of the received input prior to placing it on the stack.
Mitigation:
No known mitigation or remediation is available for this vulnerability.