This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of text encoding conversions. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-18411.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HGe Industrial Gateway Server
APPGe< 7.612Ptc Kepware Kepserverex
APPPtc< 6.12Ptc Opc Aggregator
APPPtc< 6.12Ptc Thingworx Industrial Connectivity
APPPtcall versionsPtc Thingworx Kepware Edge
APPPtc< 1.4Ptc Thingworx Kepware Server
APPPtc< 6.12Rockwellautomation Kepserver Enterprise
APPRockwellautomation< 6.12Softwaretoolbox Top Server
APPSoftwaretoolbox< 6.12
Related vulnerabilities
Buffer overflow w KEPServerEX umożliwiający crash lub wyciek danych
Zdalne wykonanie kodu w Kepware KEPServerEX – heap buffer overflow
Integer overflow umożliwiający RCE w produktach GE Digital i PTC Kepware
Nieprawidłowa walidacja indeksu tablicy w produktach GE/PTC — RCE
Stack-based buffer overflow w KEPServerEX i powiązanych produktach OPC UA