Schneider.Electric.ProClima.F1BookView.Memory.Corruption

description-logoDescription

This indicates an attack attempt to exploit a Buffer Overflow vulnerability in Schneider Electric ProClima.
The vulnerability is due to improper checking on user supplied data while the vulnerable method handles incoming request. An attacker can exploit this by tricking an unsuspecting user into visiting a malicious webpage and execute arbitrary code within the context of the application.

affected-products-logoAffected Products

Schneider Electric ProClima prior to 6.2

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Apply the latest update from the vendor
http://download.schneider-electric.com/library/downloads/WW/en/document/SEVD-2015-329-01

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2019-04-17 14.596 Sig Added
2019-03-13 14.572 Modified

References

ICSA-15-335-02