This security bulletin contains one medium risk vulnerability.
The vulnerability allows a remote attacker to cause a server-side crash.
The vulnerability exists due to a boundary error in the IEC870IP driver. A remote unauthenticated attacker can trigger stack-based buffer overflow and cause a server-side crash on the target system.Note: This vulnerability affects only the IEC870IP driver used in Vijeo Citect and Citect SCADA. Mitigation
Install updates from vendor's website.Vulnerable software versions
IEC870IP: 4.14.02Fixed software versions
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?