SB2018022805 - Denial of service in Emerson ControlWave Micro
Published: February 28, 2018
Security Bulletin ID
SB2018022805
Severity
Low
Patch available
NO
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Stack-based buffer overflow (CVE-ID: CVE-2018-5452)
The vulnerability allows a remote attacker to cause DoS condition on the target system.The weakness exists due to stack-based buffer overflow. A remote attacker can send specially crafted packets on Port 20547 and force the PLC to change its state into halt mode.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.