CRITICAL🇵🇱 Wersja polska

CVE-2024-45167

CVSS 9.8v3.1pub. 2024-08-22upd. 2025-09-03

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper deserialization, and improper restriction of operations within the bounds of a memory buffer, IDOL2 is vulnerable to Denial-of-Service (DoS) attacks and possibly remote code execution. A certain XmlMessage document causes 100% CPU consumption.

🤖 AI Analysis
How it works

An attacker sends a specially crafted XmlMessage document to the application, which causes 100% CPU resource utilization, leading to service unavailability. Improper data deserialization and lack of proper control over operations in the buffer memory area create additional conditions for potential remote code execution without the need for authentication. The attack vector is network-based, requires no user interaction or any privileges.

Impact

An attacker can cause complete system unavailability (DoS) by exhausting CPU resources, and in a scenario of exploiting a deserialization flaw — potentially gain full control over the system through remote code execution (RCE).

Mitigation & patch

Apply patches available from the manufacturer according to the references. It is recommended to check the availability of a newer client version on the manufacturer's website (uci.de). Until the update is applied, consider restricting network access to the service only to trusted hosts using a firewall.

Who is affected

UCI IDOL 2 (uciIDOL, IDOL2) in versions up to and including 2.12

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Uci Idol2

    APP
    Uci
    ≤ 2.12
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEDeserialization
CWE
References

Related vulnerabilities

CVE-2024-45166CRITICAL9.8PL ✓same product

RCE i DoS w UCI IDOL 2 przez błędną deserializację i przepełnienie bufora

CVE-2024-45168CRITICAL9.1PL ✓same product

UCI IDOL 2: brak uwierzytelnienia w komunikacji przez raw socket

CVE-2024-45169CRITICAL9.8PL ✓same product

RCE i DoS w UCI IDOL 2 przez nieprawidłową deserializację i walidację danych

CVE-2024-45165MEDIUM5.3same product

An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is sent between client and ser...