10
CVSSv2

CVE-2012-5409

Published: 01/11/2012 Updated: 21/05/2013
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

AscoServer.exe in the server in Siemens SiPass integrated MP2.6 and previous versions does not properly handle IOCP RPC messages received over an Ethernet network, which allows remote malicious users to write data to any memory location and consequently execute arbitrary code via crafted messages, as demonstrated by an arbitrary pointer dereference attack or a buffer overflow attack.

Vulnerable Product Search on Vulmon Subscribe to Product

siemens sipass integrated

Exploits

IOActive Security Advisory Title: SIEMENS Sipass Integrated 26 Ethernet Bus Arbitrary Pointer Dereference Severity: Critical Discovered by: Lucas Apa Date Reported: 09/11/12 CVE: TBD Siemens Advisory: SSA-938777 Introduction SIEMENS SiPass® Integrated is an extremely powerful and flexible access control system that provides a very high level of ...