CVE-2015-1006

Summary

CVECVE-2015-1006
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2019-05-10 14:29:00 UTC
Updated2019-10-09 23:13:00 UTC
DescriptionA vulnerable file in Opto 22 PAC Project Professional versions prior to R9.4006, PAC Project Basic versions prior to R9.4006, PAC Display Basic versions prior to R9.4f, PAC Display Professional versions prior to R9.4f, OptoOPCServer versions prior to R9.4c, and OptoDataLink version R9.4d and prior versions that were installed by PAC Project installer, versions prior to R9.4006, is susceptible to a heap-based buffer overflow condition that may allow remote code execution on the target system. Opto 22 suggests upgrading to the new product version as soon as possible.

Risk And Classification

Problem Types: CWE-119

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Application Opto22 Optodatalink All All All All
Application Opto22 Optodatalink All All All All
Application Opto22 Optoopcserver All All All All
Application Opto22 Optoopcserver All All All All
Application Opto22 Pac Display All All All All
Application Opto22 Pac Display All All All All
Application Opto22 Pac Display All All All All
Application Opto22 Pac Display All All All All
Application Opto22 Pac Project All All All All
Application Opto22 Pac Project All All All All
Application Opto22 Pac Project All All All All
Application Opto22 Pac Project All All All All

References

ReferenceSourceLinkTags
OPTO 22 Multiple Product Vulnerabilities | ICS-CERT MISC ics-cert.us-cert.gov Mitigation, Third Party Advisory, US Government Resource
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Legacy QID Mappings

  • 590556 Opto 22 Multiple Product Multiple Vulnerabilities (ICSA-15-120-01)

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report