Release date:
Updated on:
Affected Systems:
ABB MicroSCADA <9.4
Description:
--------------------------------------------------------------------------------
Bugtraq id: 63903
ABB MicroSCADA is a microcomputer-based Programmable monitoring system developed for electric power, railway, natural gas, regional heating, water supply, and petroleum networks.
The wserver.exe component (TCP port 12221) of ABB microscadahas a security vulnerability in implementation. This component does not effectively verify user data and can cause stack corruption. Remote attackers can exploit this vulnerability to execute arbitrary code in the context of the affected process.
<* Source: Andrea Micalizzi aka rgod
Link: http://secunia.com/advisories/55845/
Http://www.zerodayinitiative.com/advisories/ZDI-13-270/
Http://www.zerodayinitiative.com/advisories/ZDI-13-268/
Bytes
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
ABB
---
ABB has released a Security Bulletin (ABB-VU-PSAC-1MRS235805) and patches for this:
ABB-VU-PSAC-1MRS235805: ABB-VU-PSAC-1MRS235805
Link: Workshop