vendor:
ModbusTagServer, ScadaPhone
by:
mr_me
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: ModbusTagServer, ScadaPhone
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP3
2011
ScadaTEC ModbusTagServer & ScadaPhone (.zip) buffer overflow exploit (0day)
This exploit targets ScadaTEC ModbusTagServer and ScadaPhone software. It triggers a buffer overflow vulnerability when loading a project from a zip file. The ScadaPhone exploit bypasses DEP on Windows XP SP3, while the ModbusTagServer exploit does not. The vulnerability affects ScadaPhone versions up to 5.3.11.1230 and ModbusTagServer versions up to 4.1.1.81. The exploit has been tested on Windows XP SP3 with NX enabled.
Mitigation:
Apply the latest patch provided by the vendor. Avoid loading projects from untrusted or unknown zip files.