VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 1) [ Download XML
CVE-2010-4557
foxboro_i/a_series_batch, wonderware_inbatch: Buffer overflow in the lm_tcp service in Invensys W...
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-4557

Original

Buffer overflow in the lm_tcp service in Invensys Wonderware InBatch 8.1 and 9.0, as used in Invensys Foxboro I/A Series Batch 8.1 and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted request to port 9001.

Translation   (Show)





About This Analysis Information
Analysis Information Provider:
NIST NVD
First Published:
2010-12-17
Source Information Category:
Advisory, Alert
Last Updated:
2010-12-20




Affected Product Tags
cpe:/a:invensys:foxboro_i%2Fa_series_batch:8.1
cpe:/a:invensys:wonderware_inbatch:8.1
cpe:/a:invensys:wonderware_inbatch:9.0
 


Vulnerability Analysis Results
[Access Vector]  [?]
Undefined [?]

Local [?]
Adjacent Network [?]
X Network [?]

[Access Complexit]  [?]
Undefined [?]

High [?]
Medium [?]
X Low [?]

[Authentication]  [?]
Undefined [?]

Multiple [?]
Single [?]
X None [?]

[Confidentiality Impact]  [?]
Undefined [?]

None [?]
Partial [?]
X Complete [?]

[Integrity Impact]  [?]
Undefined [?]

None [?]
Partial [?]
X Complete [?]

[Availability Impact]  [?]
Undefined [?]

None [?]
Partial [?]
X Complete [?]

Alternatives




References
http://www.us-cert.gov/control_systems/pdf/ICSA-10-348-01.pdf




VU#647928




CONFIRM http://iom.invensys.com/EN/pdfLibrary/SecurityAlert_Invensys_SecurityAlert-LFSEC00000051_12-10.pdf




CONFIRM http://iom.invensys.com/EN/Pages/IOM_CyberSecurityUpdates.aspx




EXPLOIT-DB 15707




MISC http://aluigi.org/adv/inbatch_1-adv.txt




SECUNIA 42528




VUPEN ADV-2010-3244




Vulnerability Type Buffer Errors (CWE-119)





Copyright © 2010 JPCERT/CC All Rights Reserved.