|
|
| |
| A vulnerability allows remote attackers to execute arbitrary code on systems with vulnerable installations of the Automated Solutions Modbus TCP Slave ActiveX Control. Authentication is not required to exploit this vulnerability. |
| |
Credit:
The information has been provided by The Zero Day Initiative (ZDI).
The original article can be found at: http://www.zerodayinitiative.com/advisories/TPTI-07-15.html
|
| |
The specific flaw exists within MiniHMI.exe which binds to TCP port 502. When processing malformed Modbus requests on this port a controllable heap corruption can occur which may result in execution of arbitrary code.
Vendor Response:
Automated Solutions has issued an update to correct this vulnerability. More details can be found at:
http://www.automatedsolutions.com/pub/asmbslv/setup.exe
Disclosure Timeline:
2007.08.20 - Vulnerability reported to vendor
2007.09.07 - Digital Vaccine released to TippingPoint customers
2007.09.17 - Coordinated public release of advisory
|
|
|