Pro-face GP-Pro EX Heap Buffer Overflow Vulnerability (CVE-2016-2290)
Pro-face GP-Pro EX Heap Buffer Overflow Vulnerability (CVE-2016-2290)
Release date:
Updated on:
Affected Systems:
Proface GP-Pro EX 1.00-4.0.4
Proface GP-Pro EX
Description:
CVE (CAN) ID: CVE-2016-2290
Pro-face GP-Pro EX is an HMI Screen Editor and logic programming software.
Pro-face GP-Pro EX EX-ED earlier than 4.05.000, PFXEXEDV earlier than 4.05.000, PFXEXEDLS earlier than 4.05.000, PFXEXGRPLS earlier than 4.05.000, there is a heap buffer overflow security vulnerability in implementation, remote attackers can exploit this vulnerability to execute arbitrary code.
<* Source: Jeremy Brown
Link: https://ics-cert.us-cert.gov/advisories/ICSA-16-096-01
*>
Suggestion:
Vendor patch:
Proface
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.hmisource.com/otasuke/download/update/proex/
This article permanently updates the link address: