Multiple Schneider Electric Products CVE-2014-9200 Stack Based Buffer Overflow Vulnerability
BID:72335
Info
Multiple Schneider Electric Products CVE-2014-9200 Stack Based Buffer Overflow Vulnerability
| Bugtraq ID: | 72335 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2014-9200 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 09 2015 12:00AM |
| Updated: | Jul 15 2015 12:14AM |
| Credit: | Ariele Caltabiano (kimiya) |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Multiple Schneider Electric Products CVE-2014-9200 Stack Based Buffer Overflow Vulnerability
Multiple Schneider Electric products are prone to a remote stack-based buffer-overflow vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the application. Failed exploit attempts will result in a denial-of-service condition.
The following products are vulnerable:
Unity Pro
SoMachine
SoMove
SoMove Lite
Modbus Communication Library 2.2.6 and prior
CANopen Communication Library 1.0.2 and prior
EtherNet/IP Communication Library 1.0.0 and prior
EM X80 Gateway DTM (MB TCP/SL)
Advantys DTMs (OTB, STB)
KINOS DTM
SOLO DTM
Xantrex DTMs
Multiple Schneider Electric products are prone to a remote stack-based buffer-overflow vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the application. Failed exploit attempts will result in a denial-of-service condition.
The following products are vulnerable:
Unity Pro
SoMachine
SoMove
SoMove Lite
Modbus Communication Library 2.2.6 and prior
CANopen Communication Library 1.0.2 and prior
EtherNet/IP Communication Library 1.0.0 and prior
EM X80 Gateway DTM (MB TCP/SL)
Advantys DTMs (OTB, STB)
KINOS DTM
SOLO DTM
Xantrex DTMs
Exploit / POC
Multiple Schneider Electric Products CVE-2014-9200 Stack Based Buffer Overflow Vulnerability
An attacker can exploit this issue using readily available tools.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
An attacker can exploit this issue using readily available tools.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Multiple Schneider Electric Products CVE-2014-9200 Stack Based Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Multiple Schneider Electric Products CVE-2014-9200 Stack Based Buffer Overflow Vulnerability
References:
References:
- Schneider Electric Homepage (Schneider Electric)