UniOPC IP*Works! SSL Remote Code Execution Vulnerability
BID:50003
Info
UniOPC IP*Works! SSL Remote Code Execution Vulnerability
| Bugtraq ID: | 50003 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-5086 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 06 2011 12:00AM |
| Updated: | Apr 19 2012 01:30PM |
| Credit: | Billy Rios and Terry McCorkle |
| Vulnerable: |
Unitronics OPC Server 1.3.8 |
| Not Vulnerable: |
Unitronics UniOPC Server 2.0 |
Discussion
UniOPC IP*Works! SSL Remote Code Execution Vulnerability
UniOPC is prone to a remote code-execution vulnerability because it fails to properly sanitize input from a third-party plugin.
An attacker may leverage this issue to execute arbitrary code on a system running an affected version of the vulnerable product; failed attacks may cause denial-of-service conditions.
UniOPC prior to 2.0.0 is vulnerable; other versions may also be affected.
UniOPC is prone to a remote code-execution vulnerability because it fails to properly sanitize input from a third-party plugin.
An attacker may leverage this issue to execute arbitrary code on a system running an affected version of the vulnerable product; failed attacks may cause denial-of-service conditions.
UniOPC prior to 2.0.0 is vulnerable; other versions may also be affected.
Exploit / POC
UniOPC IP*Works! SSL Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
UniOPC IP*Works! SSL Remote Code Execution Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
UniOPC IP*Works! SSL Remote Code Execution Vulnerability
References:
References: