Stack-based buffer overflow in IEC870IP - CVE-2019-13537
Published: October 18, 2019
Vulnerability identifier: #VU21935
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-13537
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause a server-side crash.
The vulnerability exists due to a boundary error in the IEC870IP driver. A remote unauthenticated attacker can trigger stack-based buffer overflow and cause a server-side crash on the target system.
Note: This vulnerability affects only the IEC870IP driver used in Vijeo Citect and Citect SCADA.Affected software
IEC870IP
Amazon Linux AMI
Gentoo Linux
Opensuse
Amazon Linux AMI
Gentoo Linux
Opensuse
How to mitigate CVE-2019-13537
Install updates from vendor's website.
IEC870IP - update to 4.15.00