Honeywell Experion PKS CVE-2014-9189 Multiple Stack Based Buffer Overflow Vulnerabilities
BID:71740
Info
Honeywell Experion PKS CVE-2014-9189 Multiple Stack Based Buffer Overflow Vulnerabilities
| Bugtraq ID: | 71740 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-9189 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 18 2014 12:00AM |
| Updated: | Dec 18 2014 12:00AM |
| Credit: | Alexander Tlyapov, Gleb Gritsai, Kirill Nesterov, Artem Chaykin and Ilya Karpov of the Positive Technologies Research Team and Security Lab |
| Vulnerable: |
Honeywell Experion PKS R430.1 Honeywell Experion PKS R430 Honeywell Experion PKS R410.5 Honeywell Experion PKS R410 Honeywell Experion PKS R400.5 Honeywell Experion PKS R400 |
| Not Vulnerable: |
Honeywell Experion PKS R430.2 Honeywell Experion PKS R410.6 Honeywell Experion PKS R400.6 |
Discussion
Honeywell Experion PKS CVE-2014-9189 Multiple Stack Based Buffer Overflow Vulnerabilities
Honeywell Experion PKS is prone to multiple stack-based buffer-overflow vulnerabilities because the application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized buffer.
A remote attacker may exploit these issues to execute arbitrary code or cause dynamic memory corruption in the context of the affected application. Failed attempts will likely cause a denial-of-service condition.
The following versions are affected:
Honeywell Experion R40x versions prior to Experion PKS R400.6
Honeywell Experion R41x versions prior to Experion PKS R410.6
Honeywell Experion R43x versions prior to Experion PKS R430.2
Honeywell Experion PKS is prone to multiple stack-based buffer-overflow vulnerabilities because the application fails to properly bounds-check user-supplied data before copying it into an insufficiently sized buffer.
A remote attacker may exploit these issues to execute arbitrary code or cause dynamic memory corruption in the context of the affected application. Failed attempts will likely cause a denial-of-service condition.
The following versions are affected:
Honeywell Experion R40x versions prior to Experion PKS R400.6
Honeywell Experion R41x versions prior to Experion PKS R410.6
Honeywell Experion R43x versions prior to Experion PKS R430.2