5
CVSSv2

CVE-2011-4530

Published: 08/01/2012 Updated: 09/01/2012
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Siemens Automation License Manager (ALM) 4.0 up to and including 5.1+SP1+Upd1 does not properly copy fields obtained from clients, which allows remote malicious users to cause a denial of service (exception and daemon crash) via long fields, as demonstrated by fields to the (1) open_session->workstation->NAME or (2) grant->VERSION function.

Vulnerable Product Search on Vulmon Subscribe to Product

siemens automation license manager

Exploits

####################################################################### Luigi Auriemma Application: Siemens Automation License Manager supportautomationsiemenscom/WW/llisapidll?func=cslibcsinfo&lang=en&siteid=cseus&aktprim=0&extranet=standard&viewreg=WW&objid=10805384 ...