An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper deserialization, and improper restriction of operations within the bounds of a memory buffer, IDOL2 is vulnerable to Denial-of-Service (DoS) attacks and possibly remote code execution. A certain XmlMessage document causes 100% CPU consumption.
An attacker sends a specially crafted XmlMessage document to the application, which causes 100% CPU resource utilization, leading to service unavailability. Improper data deserialization and lack of proper control over operations in the buffer memory area create additional conditions for potential remote code execution without the need for authentication. The attack vector is network-based, requires no user interaction or any privileges.
An attacker can cause complete system unavailability (DoS) by exhausting CPU resources, and in a scenario of exploiting a deserialization flaw — potentially gain full control over the system through remote code execution (RCE).
Apply patches available from the manufacturer according to the references. It is recommended to check the availability of a newer client version on the manufacturer's website (uci.de). Until the update is applied, consider restricting network access to the service only to trusted hosts using a firewall.
UCI IDOL 2 (uciIDOL, IDOL2) in versions up to and including 2.12
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HUci Idol2
APPUci≤ 2.12
Related vulnerabilities
RCE i DoS w UCI IDOL 2 przez błędną deserializację i przepełnienie bufora
UCI IDOL 2: brak uwierzytelnienia w komunikacji przez raw socket
RCE i DoS w UCI IDOL 2 przez nieprawidłową deserializację i walidację danych
An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is sent between client and ser...