SB2018022805 - Denial of service in Emerson ControlWave Micro



SB2018022805 - Denial of service in Emerson ControlWave Micro

Published: February 28, 2018

Security Bulletin ID SB2018022805
Severity
Low
Patch available
NO
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Stack-based buffer overflow (CVE-ID: CVE-2018-5452)

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to stack-based buffer overflow. A remote attacker can send specially crafted packets on Port 20547 and force the PLC to change its state into halt mode.

Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.