10
CVSSv2

CVE-2011-5007

Published: 25/12/2011 Updated: 21/05/2013
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Stack-based buffer overflow in the CmpWebServer component in 3S CoDeSys 3.4 SP4 Patch 2 and previous versions, as used on the ABB AC500 PLC and possibly other products, allows remote malicious users to execute arbitrary code via a long URI to TCP port 8080.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

3ssoftware codesys

Exploits

/* See Also: aluigialtervistaorg/adv/codesys_1-advtxt CoDeSys v23 Industrial Control System Development Software Remote Buffer Overflow Exploit for CoDeSys Scada webserver Author : Celil UNUVER, SignalSEC Labs wwwsignalseccom Tested on WinXP SP1 EN THIS CODE IS FOR EDUCATIONAL PURPOSES ONLY! --snip-- root@bt:~# /codesys 192168136 ...
## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/core' class Metasploit3 < Msf::Exploit::Remote Rank = NormalRanking inclu ...