#VU21935 Stack-based buffer overflow


Published: 2019-10-18

Vulnerability identifier: #VU21935

Vulnerability risk: Medium

CVSSv3.1:

CVE-ID: CVE-2019-13537

CWE-ID: CWE-121

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
IEC870IP
Hardware solutions / Drivers

Vendor: AVEVA Software, LLC.

Description

The vulnerability allows a remote attacker to cause a server-side crash.

The vulnerability exists due to a boundary error in the IEC870IP driver. A remote unauthenticated attacker can trigger stack-based buffer overflow and cause a server-side crash on the target system.

Note: This vulnerability affects only the IEC870IP driver used in Vijeo Citect and Citect SCADA.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

IEC870IP: 4.14.02


CPE

External links
http://ics-cert.us-cert.gov/advisories/icsa-19-290-01
http://sw.aveva.com/hubfs/assets-2018/pdf/security-bulletin/SecurityBulletin_LFSec139.pdf


Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?


Latest bulletins with this vulnerability