Easylon OPC Server Arbitrary Code Execution Vulnerability
BID:26876
Info
Easylon OPC Server Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 26876 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-4473 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Dec 14 2007 12:00AM |
| Updated: | Dec 17 2007 09:01PM |
| Credit: | NeuralBit is credited with the discovery of this vulnerability. |
| Vulnerable: |
Gesytec GmbH Easylon OPC Server 2.30.32 Gesytec GmbH Easylon OPC Server 2.0 |
| Not Vulnerable: |
Gesytec GmbH Easylon OPC Server 2.3.44 |
Discussion
Easylon OPC Server Arbitrary Code Execution Vulnerability
Easylon OPC Server is prone to a vulnerability that lets attackers execute arbitrary machine code in the context of the affected application or to cause denial-of-service conditions.
This issue affects versions prior to Easylon OPC Server 2.3.44.
Easylon OPC Server is prone to a vulnerability that lets attackers execute arbitrary machine code in the context of the affected application or to cause denial-of-service conditions.
This issue affects versions prior to Easylon OPC Server 2.3.44.
Exploit / POC
Easylon OPC Server Arbitrary Code Execution Vulnerability
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Easylon OPC Server Arbitrary Code Execution Vulnerability
Solution:
The vendor has released Easylon OPC Server 2.3.44 to address this issue. Please see the referenced advisories for more information.
Solution:
The vendor has released Easylon OPC Server 2.3.44 to address this issue. Please see the referenced advisories for more information.
References
Easylon OPC Server Arbitrary Code Execution Vulnerability
References:
References:
- Easylon OPC Homepage (Gesytec)
- US-CERT Vulnerability Note VU#205073 (US-CERT)