Pro-face GP-Pro EX out-of-bounds read Vulnerability (CVE-2016-2291)
Pro-face GP-Pro EX out-of-bounds read Vulnerability (CVE-2016-2291)
Release date:
Updated on:
Affected Systems:
Proface GP-Pro EX 1.00-4.0.4
Proface GP-Pro EX
Description:
CVE (CAN) ID: CVE-2016-2291
Pro-face GP-Pro EX is an HMI Screen Editor and logic programming software.
Pro-face GP-Pro EX EX-ED versions earlier than 4.05.000, PFXEXEDV earlier than 4.05.000, PFXEXEDLS earlier than 4.05.000, PFXEXGRPLS earlier than 4.05.000, security vulnerabilities exist in implementation, remote attackers can exploit this vulnerability to execute arbitrary code or cause DoS attacks.
<* Source: Jeremy Brown
Link: https://ics-cert.us-cert.gov/advisories/ICSA-16-096-01
*>
Suggestion:
Vendor patch:
Proface
-------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.hmisource.com/otasuke/download/update/proex/
This article permanently updates the link address: