vendor:
Optima APIFTP Server
by:
Luigi Auriemma
7.5
CVSS
HIGH
NULL pointer and endless loop
119, 835
CWE
Product Name: Optima APIFTP Server
Affected Version From: 1.5.2.13
Affected Version To: 1.5.2.13
Patch Exists: YES
Related CWE: N/A
CPE: a:optimalog:optima_apiftp_server
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2011
Optima APIFTP Server <= 1.5.2.13 Vulnerabilities
Optima is a suite of automation software for controlling PLC via SCADA/HMI interface. APIFTP Server is a file server for working with remote files located on shared folders. NULL pointer exploitable through too long path names. The effect is the displaying of a MessageBox with the error and the continuing of the execution that will lead to a stack exaustion after some seconds and the termination of the server. Endless loop with CPU at 100% caused by incomplete packets.
Mitigation:
Upgrade to the latest version of Optima APIFTP Server