WellinTech KingSCADA CVE-2014-0787 Stack-Based Buffer Overflow Vulnerability
BID:66709
Info
WellinTech KingSCADA CVE-2014-0787 Stack-Based Buffer Overflow Vulnerability
| Bugtraq ID: | 66709 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2014-0787 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 08 2014 12:00AM |
| Updated: | Aug 01 2014 12:22AM |
| Credit: | Anonymous researcher working with HP�??s Zero Day Initiative |
| Vulnerable: |
Wellintech KingSCADA 3.0 |
| Not Vulnerable: | |
Discussion
WellinTech KingSCADA CVE-2014-0787 Stack-Based Buffer Overflow Vulnerability
WellinTech KingSCADA is prone to a stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
An attacker can exploit this issue to execute arbitrary code in the context of the application. Failed attacks will likely cause denial-of-service conditions.
KingSCADA versions prior to 3.1.2.13 is vulnerable.
WellinTech KingSCADA is prone to a stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
An attacker can exploit this issue to execute arbitrary code in the context of the application. Failed attacks will likely cause denial-of-service conditions.
KingSCADA versions prior to 3.1.2.13 is vulnerable.
Exploit / POC
WellinTech KingSCADA CVE-2014-0787 Stack-Based Buffer Overflow Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
WellinTech KingSCADA CVE-2014-0787 Stack-Based Buffer Overflow Vulnerability
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
References
WellinTech KingSCADA CVE-2014-0787 Stack-Based Buffer Overflow Vulnerability
References:
References:
- KingSCADA Homepage (Wellintech)