Showing posts with label Buffer Overflow. Show all posts
Showing posts with label Buffer Overflow. Show all posts

Tuesday, February 5, 2013

ICS-CERT Publishes Ecava Advisory


Today the DHS ICS-CERT published an advisory for a buffer overflow vulnerability in the Ecava IntegraXor application. The vulnerability was reported by Andrew Brooks in a coordinated disclosure.

ICS-CERT reports that a moderately skilled attacker utilizing a social engineering attack could remotely exploit this vulnerability to run arbitrary code on the system. Ecava has produced an updated version of the affected application that has been verified by Brooks to correct the vulnerability.

Thursday, January 24, 2013

ICS-CERT Advisory for Beijer Electronics Products


Today the DHS ICS-CERT published an alert for products from Beijer Electronics. The buffer overflow vulnerability that was reported by Kuang-Chun Hung of Information and Communication Security Technology Center (ICST) in a coordinated disclosure.

ICS-CERT reports that the vulnerability requires direct access to the system and that it would be difficult to craft “a working exploit for this vulnerability” (pg 3). Beijer Electronics has produced updated versions of the affected software and Kuang-Chun has verified that they correct the vulnerability.

Friday, June 15, 2012

ICS-CERT Publishes Sielco Sistemi Winlog Alert


Yesterday the DHS ICS-CERT published an alert concerning a buffer overflow vulnerability in the Sielco Sistemi Winlog HMI product. The uncoordinated disclosure was initiated by Michael Messner. Not much info at this point beyond the report that an a specially crafted request sent to a specific TCP could result in remote execution of arbitrary code. Seems like a pretty typical HMI vulnerability.

It is amazing that vulnerabilities like this are still being reported. This is such a common, basic vulnerability that one would like to think that vendors had gone back and checked for these. I kind of understand why a researcher might not want to waste time on a coordinated disclosure on such a basic vulnerability as this.
 
/* Use this with templates/template-twocol.html */