Out-of-bounds read in Schneider Electric products - CVE-2016-10395
Published: May 24, 2018 / Updated: May 28, 2018
Vulnerability identifier: #VU13021
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-10395
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to out-of-bounds memory read. A remote attacker can trigger memory corruption and cause the service to crash.
Affected software
Energy Expert
StruxureWare Power Monitoring Expert
EcoStruxure Power Monitoring Expert
StruxureWare Power Monitoring Expert
EcoStruxure Power Monitoring Expert
How to mitigate CVE-2016-10395
Install update from vendor's website.