Siemens SiPass Integrated 'SiPass server' Component Buffer Overflow Vulnerability
BID:55835
Info
Siemens SiPass Integrated 'SiPass server' Component Buffer Overflow Vulnerability
| Bugtraq ID: | 55835 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2012-5409 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 09 2012 12:00AM |
| Updated: | Oct 31 2012 09:11PM |
| Credit: | Lucas Apa of IOActive |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Siemens SiPass Integrated 'SiPass server' Component Buffer Overflow Vulnerability
Siemens SiPass Integrated is prone to a remote buffer-overflow vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Siemens SiPass integrated MP2.6 and earlier are affected.
Siemens SiPass Integrated is prone to a remote buffer-overflow vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Siemens SiPass integrated MP2.6 and earlier are affected.
Exploit / POC
Siemens SiPass Integrated 'SiPass server' Component Buffer Overflow Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
Siemens SiPass Integrated 'SiPass server' Component Buffer Overflow Vulnerability
Solution:
A vendor patch is available. Please see the references for more information.
Solution:
A vendor patch is available. Please see the references for more information.
References
Siemens SiPass Integrated 'SiPass server' Component Buffer Overflow Vulnerability
References:
References: