7.6
CVSSv2

CVE-2010-4709

Published: 28/01/2011 Updated: 17/08/2017
CVSS v2 Base Score: 7.6 | Impact Score: 10 | Exploitability Score: 4.9
VMScore: 765
Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

Heap-based buffer overflow in Automated Solutions Modbus/TCP Master OPC Server prior to 3.0.2 allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via a MODBUS response packet with a crafted length field.

Vulnerable Product Search on Vulmon Subscribe to Product

automatedsolutions modbus\\/tcp master opc server 2.12.1

automatedsolutions modbus\\/tcp master opc server 2.12

automatedsolutions modbus\\/tcp master opc server 2.9

automatedsolutions modbus\\/tcp master opc server 2.8

automatedsolutions modbus\\/tcp master opc server 2.7

automatedsolutions modbus\\/tcp master opc server 2.6b

automatedsolutions modbus\\/tcp master opc server 2.6a

automatedsolutions modbus\\/tcp master opc server 2.2a

automatedsolutions modbus\\/tcp master opc server 2.2

automatedsolutions modbus\\/tcp master opc server 2.11

automatedsolutions modbus\\/tcp master opc server 2.10

automatedsolutions modbus\\/tcp master opc server 2.7f

automatedsolutions modbus\\/tcp master opc server 2.7a

automatedsolutions modbus\\/tcp master opc server 2.6

automatedsolutions modbus\\/tcp master opc server 2.5

automatedsolutions modbus\\/tcp master opc server 2.1

automatedsolutions modbus\\/tcp master opc server 2.0a

automatedsolutions modbus\\/tcp master opc server 3.0.0

automatedsolutions modbus\\/tcp master opc server 2.12.3

automatedsolutions modbus\\/tcp master opc server 2.9_build_2.9.3

automatedsolutions modbus\\/tcp master opc server 2.9.1

automatedsolutions modbus\\/tcp master opc server 2.7d

automatedsolutions modbus\\/tcp master opc server 2.7e

automatedsolutions modbus\\/tcp master opc server 2.3a

automatedsolutions modbus\\/tcp master opc server 2.3

automatedsolutions modbus\\/tcp master opc server

automatedsolutions modbus\\/tcp master opc server 2.9.5

automatedsolutions modbus\\/tcp master opc server 2.9.4

automatedsolutions modbus\\/tcp master opc server 2.7b

automatedsolutions modbus\\/tcp master opc server 2.7c

automatedsolutions modbus\\/tcp master opc server 2.4a

automatedsolutions modbus\\/tcp master opc server 2.4

automatedsolutions modbus\\/tcp master opc server 2.0_build_1

automatedsolutions modbus\\/tcp master opc server 2.0

Exploits

#!/usr/bin/python # asmb-heappy # Automated Solutions Modbus/TCP OPC Server Remote Heap Corruption PoC # Jeremy Brown [0xjbrown41-gmail-com] # Jan 2011 # # A specially crafted length field in a MODBUS packet header can trigger heap corruption # # 00408312 |> 8B5424 3C MOV EDX,DWORD PTR SS:[ESP+3C] -> move length into edx # 00408316 ...