vendor:
SEIG Modbus Driver
by:
Alejandro Parodi
9.3
CVSS
HIGH
Remote Code Execution
119
CWE
Product Name: SEIG Modbus Driver
Affected Version From: v3.4
Affected Version To: v3.4
Patch Exists: NO
Related CWE: CVE-2013-0662
CPE: a:schneider_electric:seig_modbus_driver:3.4
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows XP SP3
2018
SEIG Modbus 3.4 – Remote Code Execution
A vulnerability exists in SEIG Modbus 3.4 which allows remote code execution. The vulnerability is due to a stack-based buffer overflow in the SEIG Modbus 3.4 service. An attacker can send a specially crafted packet to the service to trigger the buffer overflow and execute arbitrary code. This vulnerability is tracked as CVE-2013-0662.
Mitigation:
No known mitigation is available for this vulnerability.