vendor:
WinPLC7
by:
james fitts
7,5
CVSS
HIGH
Stack Buffer Overflow
119
CWE
Product Name: WinPLC7
Affected Version From: WinPLC7 <= 5.0.45.5921
Affected Version To: WinPLC7 <= 5.0.45.5921
Patch Exists: NO
Related CWE: CVE-2017-5177
CPE: a:vipa_automation:winplc7
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 EN
2017
VIPA Authomation WinPLC7 recv Stack Buffer Overflow
This module exploits a stack based buffer overflow found in VIPA Automation WinPLC7 <= 5.0.45.5921. The overflow is triggered when WinPLC7 connects to a remote server and accepts a malicious packet. The first 2 bytes of this packet are read in and used as the size value for a later recv function. If a size value of sufficiently large size is supplied a stack buffer overflow will occur.
Mitigation:
No known mitigation or remediation for this vulnerability