This application requires Javascript for optimal performance.

CoDeSys.SCADA.Remote.Code.Execution

Release Date

Jan 19, 2012

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt against a buffer overflow vulnerability in CoDeSys SCADA.

The vulnerability is caused by an error when the vulnerable software handles a overly long URI. It allows a remote attacker to execute arbitrary code via sending a crafted URI.

Affected Products

CoDeSys v2.3

Recommended Actions

Currently we are not aware of any vendor supplied patch for this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2011-5007

Reference/s

http://www.exploit-db.com/exploits/18187/

Reference: VID-30528