Release date:
Updated on: 2013-07-31
Affected Systems:
Ge-ip Proficy CIMPLICITY 8.x
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2013-2785
GE Proficy CIMPLICITY is a client/server business visualization and control solution.
When decoding passwords in Proficy HMI/SCADA-CIMPLICITY 8.2, 8.1, and 8.0, The CimWebServer component has a boundary error, and requests with a long szPassword field will cause stack buffer overflow; when Broadcase/Init is processed, the CimWebServer component has a boundary error. If the szOptions field is too long, the stack buffer overflows.
<* Source: ZombiE
Amisto0x07
Link: http://secunia.com/advisories/54348/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Ge-ip
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.ge-ip.com/products/proficy-hmi-scada-cimplicity/p2819
Proficy HMI/SCADA-CIMPLICITY 8.2 SIM 19:
Http://support.ge-ip.com/support/index? Page = dwchannel & id = DN4014
Proficy HMI/SCADA-CIMPLICITY 8.1 SIM 25:
Http://support.ge-ip.com/support/index? Page = dwchannel & id = DN4024
Proficy HMI/SCADA-CIMPLICITY 8.0 SIM 27:
Http://support.ge-ip.com/support/index? Page = dwchannel & id = DN4013